- Data processed
- LaunchPad: JSM Assets schema definitions (object type names, attribute configurations, reference types, and optional sample data for seeding). Second Chance: the summary and description of the request being viewed (read transiently to extract keywords, not stored) plus the knowledge base articles the viewing user is entitled to see.
- Data residency
- All processing occurs within Atlassian Forge infrastructure, hosted on AWS regions used by Atlassian. The apps do not transfer customer operational data outside the Forge platform.
- Data portability
- LaunchPad: schemas and data it creates remain in the customer's JSM Assets instance after uninstall and are not locked into the app. Second Chance: it creates no Jira data; all app storage (settings, coverage cache, feedback events, metrics) is purged from Forge storage on uninstall.
- Storage encryption
- Forge Storage is encrypted at rest with AES 256 and in transit with TLS 1.2 or later, managed by the Atlassian platform.
- Privacy by design
- The apps minimise data collection, process only the limited data required to operate, respect tenant boundaries enforced by Forge, and default to the most privacy-preserving configuration.
- External calls
- The only external endpoint the apps communicate with is api.atlassian.com for Atlassian API operations. No third-party services, large language models, or AI APIs. The apps never request Atlassian user passwords, API tokens, or personal credentials. Authentication is handled entirely through Atlassian Forge app authentication.
- Logging & metrics
- Application logs do not contain request or knowledge base content. Operational logs and stored records may include technical identifiers such as Atlassian Account ID strictly for audit and debugging. Lightweight, sampled operational metrics are stored in Forge storage in the customer's own tenant, never transmitted externally, and removed on uninstall.