ChangeGuard for Jira Security Policy
Last updated: 2026-08-05
Architecture and access
Section titled “Architecture and access”ChangeGuard is hosted on Atlassian Forge and declares no external remotes or data egress. It uses Jira user-context reads where practical, Jira administrator permission checks for privileged operations, app-context writes only for app-owned enforcement/reporting data, and bounded non-admin guidance.
Secure development and release
Section titled “Secure development and release”Changes pass automated tests, lint, static build, dependency audit, CycloneDX SBOM generation, Forge lint, workflow validation, and source/provenance checks. Development builds are tagged. Production promotion reuses an existing clean Forge build, proves its source commit, and records deployment evidence behind protected approval.
Vulnerability management
Section titled “Vulnerability management”Moderate-or-higher production dependency findings block the security audit. Flowdence reviews dependency alerts and Marketplace security tickets under its vulnerability-management process. No security certification or Cloud Fortified status is claimed unless explicitly published after approval.
Reporting
Section titled “Reporting”Report suspected vulnerabilities to security [at] flowdence.io with a description, safe reproduction, impact, and contact details. Do not include live secrets or unnecessary customer data. Flowdence coordinates investigation, remediation, Atlassian/customer notification, and disclosure under its incident process and applicable duties.