Security Policy
MigrationMonitor · Effective Date: September 2026 · Developer: Appcento (David Day)
Overview
This Security Policy describes the secure design and operational practices for MigrationMonitor, a Jira Cloud migration monitoring app built on the Atlassian Forge platform.
Hosting and Infrastructure
MigrationMonitor is built on the Atlassian Forge platform and runs entirely within Atlassian's infrastructure. There are no external servers, databases, or third-party backends hosted by Appcento. All compute resources are provided by Atlassian as part of the Forge runtime.
Data Handling
MigrationMonitor is designed with a zero-external-storage architecture:
- Runs within Jira: All processing occurs inside your Jira Cloud instance via Atlassian Forge. No data leaves your Atlassian workspace.
- Atlassian KVS storage: Migration monitoring data is stored in Atlassian Key-Value Store (KVS), which is encrypted at rest by Atlassian. Data is only accessible within your Jira Cloud instance.
- No external storage: The App does not store any data on external servers, cloud storage, or third-party services.
- User-controlled deletion: All stored data can be cleared at any time via the "Clear History" feature. Uninstalling the App automatically deletes all stored data.
Authentication
MigrationMonitor is a Forge app that uses Atlassian's built-in authentication mechanism:
- OAuth 2.0: The App uses Atlassian's OAuth 2.0 flow for authentication. No user credentials are stored or transmitted outside Atlassian's infrastructure.
- Jira API tokens: API access is managed through Atlassian's token system. Tokens are scoped to the minimum required permissions and can be revoked at any time.
- No separate login: Users authenticate through their existing Jira Cloud credentials. No additional accounts or passwords are required.
Data Access and Permissions
The App uses Atlassian's OAuth mechanism to access Jira data. Only the minimum required API scopes are requested:
| Scope | Purpose |
|---|---|
read:jira-work |
Read issue metadata and field values for migration monitoring and validation |
read:jira-project |
Read project configurations and workflows for readiness checks |
These are the minimum scopes required for the App to function. No write permissions are required for monitoring-only features.
Encryption
All encryption is handled by Atlassian's infrastructure:
- Data in transit: All communication between the App and Jira's REST API is encrypted via TLS as enforced by Atlassian's infrastructure.
- Data at rest: Data stored in Atlassian KVS is encrypted at rest by Atlassian's platform-level encryption.
- No custom encryption: The App relies on Atlassian's industry-standard encryption rather than implementing custom encryption layers.
Network Security
The App makes no network calls to external third-party services.
- All API communication is with Jira's REST API through Forge's secure runtime and OAuth mechanism.
- There is no egress from Atlassian's Forge runtime to external endpoints outside Atlassian unless explicitly added and approved in the app manifest.
- The App does not use external analytics, monitoring, or telemetry services.
Vulnerability Reporting
Appcento takes security seriously. If you discover a security vulnerability in MigrationMonitor, please report it responsibly:
- Email: Send a detailed report to [email protected]
- Response time: We will acknowledge receipt within 48 hours and provide an initial assessment within 5 business days.
- Disclosure: We request that you do not publicly disclose the vulnerability until we have had a chance to address it.
Compliance
MigrationMonitor complies with the following standards and frameworks:
- Atlassian Marketplace compliance: The App has passed Atlassian's security review and listing requirements.
- GDPR: As the App processes no personal data outside of Jira Cloud and makes no external data transfers, it is designed to support GDPR compliance for installed instances.
- SOC 2: Atlassian's Forge platform is SOC 2 compliant. MigrationMonitor inherits these platform-level controls.
- Atlassian Trust Center: The App inherits Atlassian's platform-level security controls and certifications. Refer to:
Incident Response
In the event of a security incident or vulnerability discovery:
- Appcento will coordinate with affected customers and Atlassian as required.
- Notifications will be sent to impacted contacts via the support email channel.
- Patches and mitigations will be applied as quickly as possible through the Forge deployment pipeline.
- For security issues, contact: [email protected]
Changes to This Policy
We may update this Security Policy from time to time. Any changes will be reflected by updating the "Effective Date" at the top of this document.
Contact
For security questions or to report a vulnerability, contact:
Email: [email protected]
Website: https://appcento.com