Runbooks for Confluence and Jira

Security

Last updated 30 September 2026

Reporting a vulnerability

Write to security@apps.sundar.am with a description of the issue, the steps to reproduce it, and what an attacker could gain. You will have an acknowledgement within five working days. Please give a reasonable chance to fix the issue before you disclose it publicly.

Fixes follow the resolution timeframes in Atlassian's Security Bug Fix Policy, which sets them by CVSS score: 10 days for critical, 4 weeks for high, 12 weeks for medium and 25 weeks for low. If a vulnerability or incident affects customers, the developer will notify affected customers and Atlassian.

How the app is built

The app runs entirely on Atlassian Forge, inside your Atlassian site.

What this app does not have

Runbooks for Confluence and Jira is maintained by one developer. It holds no SOC 2, ISO 27001 or similar certification, and it is not enrolled in the Marketplace bug bounty programme. How personal data is handled is set out in the privacy policy.