Security and trust

Designed to minimize access and data exposure.

ReleaseProof uses a read-only Jira permission model, deterministic rules, minimized frontend results, and fail-closed processing.

Security posture

Designed around explicit boundaries.

01

Read-only Jira scope

read:jira-work permits retrieval of required Jira data through Jira user context. The app does not request Jira write permissions.

02

App-owned configuration

storage:app stores ReleaseProof project configuration within the Forge app context.

03

No generative AI path

The readiness engine uses code-based deterministic rules. It does not send Jira data to an LLM.

04

Minimized Custom UI result

Full descriptions and acceptance text sources are excluded from the public analysis value.

05

Fail-closed collection

Incomplete pagination, malformed pages, or unsafe issue mappings abort the analysis.

06

Human decision boundary

ReleaseProof presents evidence. It neither changes Jira nor makes the release decision.

Data handling

Only signals required for the workflow.

Jira issue signalsProcessed during analysisDetermine explicit rule outcomes
Project configurationForge app storageKeep project-level scope and supported field choice
Analysis outputReturned to Custom UIDisplay score, findings, and minimized evidence
Website lead dataConfigured lead adapterRespond to an explicit contact or early-access request

Assurance boundaries

Claims we do not make.

  • No claim of SOC 2, ISO 27001, or other certification
  • No autonomous approval or compliance determination
  • No promise of zero risk or complete defect detection
  • No substitute for customer validation, access governance, or retention policy
A bounded analysis path
  1. Jira scopeRead required issue signals through Forge
  2. Deterministic rulesEvaluate seven explicit conditions
  3. Minimized resultReturn score, findings, and display data
  4. Human gateReview evidence and make the decision

Hosting and processing boundary

The Jira app and public website are separate systems.

The Atlassian-hosted application architecture runs release analysis inside Atlassian Forge. The public ReleaseProof website is hosted separately on Vercel. Jira release-analysis data is not processed by the marketing website.

External services and subprocessors

The current Jira analysis path does not use an external product database, generative AI provider, or marketing-site service. Vercel hosts only this public website. Lead delivery is a separate, deployment-configured service and must be documented before launch.

Responsible disclosure

Report a suspected security issue through the contact route. Do not include credentials, production Jira content, or personal data in the initial message.

Contact security

Need a focused security review?

Use the contact form to request architecture, permission, and data-flow details relevant to your evaluation.