Skip to content

ChangeGuard for Jira Security Policy

Last updated: 2026-08-05

ChangeGuard is hosted on Atlassian Forge and declares no external remotes or data egress. It uses Jira user-context reads where practical, Jira administrator permission checks for privileged operations, app-context writes only for app-owned enforcement/reporting data, and bounded non-admin guidance.

Changes pass automated tests, lint, static build, dependency audit, CycloneDX SBOM generation, Forge lint, workflow validation, and source/provenance checks. Development builds are tagged. Production promotion reuses an existing clean Forge build, proves its source commit, and records deployment evidence behind protected approval.

Moderate-or-higher production dependency findings block the security audit. Flowdence reviews dependency alerts and Marketplace security tickets under its vulnerability-management process. No security certification or Cloud Fortified status is claimed unless explicitly published after approval.

Report suspected vulnerabilities to security [at] flowdence.io with a description, safe reproduction, impact, and contact details. Do not include live secrets or unnecessary customer data. Flowdence coordinates investigation, remediation, Atlassian/customer notification, and disclosure under its incident process and applicable duties.