Skip to content

ChangeGuard Data Handling Disclosure

Last updated: 2026-08-05

CategoryExamplesPurpose
Jira contextSite, project, issue, work type, status, resolution, labels, Fix Versions, workflow/transition identifiersPolicy evaluation, simulation, guidance, compliance, and enforcement
Policy dataNames, scope, requirements, mode, immutable revisions/events/releasesAuthor, test, publish, restore, and prove policy state
GovernanceFindings, waivers, reasons, status provenance, scan summariesReview drift and controlled exceptions
EvidenceSimulation summaries, compliance values, Audit events, bounded CSV/JSON exportsReporting and review
Account registryAtlassian account ID plus random actor referencePersonal-data reporting and unlinkable immutable provenance after erasure
SupportMinimized details a customer submitsDiagnose and resolve support requests

ChangeGuard uses Atlassian Forge hosted storage and Jira app properties. The manifest declares no remotes or external egress. Flowdence operates no separate ChangeGuard database or object store.

Jira administrator authorization protects policy administration, Governance, Health details, and exports. Regular issue users receive a bounded guidance projection. Paid-license checks reduce/stop app behavior for an explicitly inactive subscription, and validators permit Jira operations rather than trapping users.

Audit events use a 30-day TTL/filter; async simulation jobs use a 7-day TTL. Raw account-ID mappings are reported weekly and erased on Atlassian closed/updated responses. Policy and governance retention follows documented product lifecycle and protected-reference rules. Contact https://flowdence.io/support for a customer deletion request.

Do not include secrets, passwords, PATs, or unrestricted personal data in policies, waiver reasons, JQL, screenshots, exports, or support requests.