Security and privacy
- Runs on Atlassian. The app is built on Atlassian Forge and runs entirely inside Atlassian's infrastructure. It declares no external network access. Nothing is sent to us or to any third party.
- No data storage. Version 1 stores nothing. Planned features that need storage (per-user team cache, Team to group mapping) will use Forge's hosted storage inside your Atlassian tenancy and will be documented here first.
- Permissions respected. Issue data is read as the person using the app, so results never exceed what that person can already see in Jira.
- Scopes requested and why | Scope | Used for | |---|---| |
read:jira-work| Read issues and fields for the gadget, panel and JQL functions | |read:jira-user| Resolve the current viewer for "you are a member" | |view:team:teams| List Atlassian Teams (name, description, size) | |view:membership:teams| Determine whether the viewer belongs to a team | - No write scopes. The app cannot modify issues, fields, teams or settings.
- Data residency. Forge apps follow the data residency of your Atlassian site.
- Vulnerability reports: email the support address in Support with "security" in the subject.
Was this page helpful? Email support@mortiseapps.com.