Security Policy
Collected Data and Storage
-
SummMap is a Jira and Service Desk add-on (further referred to as App) which operates within the
browser
and can
only be obtained and installed via the Atlassian Marketplace.
-
The app utilizes the Forge
serverless app development platform as provided by Atlassian.
-
The following ACE permission scopes are required to operate the app: (1) - read:jira-work (Read Jira
project and issue data, search for issues and objects associated with issues like attachments and
worklogs)
- storage:app (Enables the Forge storage API.).
-
SumMap does not store any personal information. Users have the option to store individual SumMap
configurations for their
convenience. All
data is stored in the Forge hosted storage. No data is ever shared
with any
third-party organization.
-
When users interact with the app, the majority of the traffic occurs directly between the user's browser
and the
Atlassian Cloud REST APIs. Browser requests are evaluated on the Jira instance within the context of the
executing user, meaning each user can only access/edit data permitted by their Jira permission
configuration.
-
No data is logged and no user behavior is tracked (e.g., through Google Analytics).
-
It is the customer's sole responsibility to provide all required mechanisms to maintain the privacy and
security
of the data and access to the app.
Security Measures
Please refer to the relevant Atlassian Forge security documentation including but not limited to:
Support Data
-
Customers may choose to share additional information with us to receive support (e.g., use cases, bug
reports).
It is the customer's responsibility to sanitize all information (URLs, sensitive data in logs,
screenshots,
etc.) before sharing it with us.
-
All such information is saved in a Jira Cloud instance provided by Atlassian, and only our employees
have access
to it.
-
We may share such information with Atlassian at our discretion if we believe it may help provide better
support
to the client. It will not be shared with any other third-party without explicit written authorization
from the
customer.
Acceptance
-
By installing the app, the customer agrees to all the terms described in this policy.