Cloud Security Statement
Live Change Alerts for Jira · Last updated: 4 October 2026
1. Overview
Live Change Alerts for Jira is built on the Atlassian Forge platform. This statement describes how we use Forge and which controls we apply to help protect customer data.
2. Hosting & Architecture
- All application logic executes within Atlassian Forge's isolated runtime.
- Data used by the App is stored using Forge storage services and Jira properties within Atlassian's infrastructure. Live updates are delivered through Forge Realtime.
- The App makes no connections to external servers: no data leaves Atlassian.
- No production Jira content is stored on servers operated directly by MyStatement, Inc. unless explicitly agreed for support or troubleshooting.
3. Data Protection
- Data at rest is encrypted using Atlassian-managed encryption.
- Data in transit is protected using TLS (HTTPS) enforced by Atlassian.
- The App stores as little as possible: temporary presence records holding Atlassian account identifiers, which expire after 10 minutes, and on/off settings. Work item content is read to describe a change and is not stored.
- The App stores no passwords, PINs or other secrets.
- Access to configuration and logs is restricted to authorized personnel of MyStatement, Inc. under least-privilege principles.
4. Permissions
The App requests only the Jira permissions it needs:
- Read work items, their change history and comments, to detect and describe changes.
- Read user display names, to show who made a change and who is viewing.
- Forge storage, to keep the temporary list of who is viewing each work item.
- Write user, project and app properties, to save the on/off settings.
5. Application Security Practices
- Use of secure coding practices and regular internal reviews.
- Separation of environments for development, staging and production.
- The identity of a viewer and the work item they have open are taken from the request context signed by Forge, so a browser cannot report presence on behalf of another user or for a work item it does not have open.
6. Incident Response
In the event we become aware of a security incident affecting data processed by the App, we will investigate promptly and, where required, notify affected customers in cooperation with Atlassian's incident management processes.
7. Vulnerability Reporting
We encourage responsible disclosure of potential vulnerabilities.
Please contact us at alerts@mystatement.atlassian.net