Security
Reporting a vulnerability
Write to security@apps.sundar.am with a description of the issue, the steps to reproduce it, and what an attacker could gain. You will have an acknowledgement within five working days. Please give a reasonable chance to fix the issue before you disclose it publicly.
Fixes follow the resolution timeframes in Atlassian's Security Bug Fix Policy, which sets them by CVSS score: 10 days for critical, 4 weeks for high, 12 weeks for medium and 25 weeks for low. If a vulnerability or incident affects customers, the developer will notify affected customers and Atlassian.
How the app is built
The app runs entirely on Atlassian Forge, inside your Atlassian site.
- No outside connections. The app declares no remote back end and no outbound network permission, so it cannot send your data anywhere outside Atlassian. It exposes no web trigger.
- Atlassian-hosted storage only. Everything the app keeps is in Forge's hosted storage in your site, which follows Atlassian's data residency programme. The developer operates no servers and holds no copy of your data.
- Read-only access to Confluence and Jira. The app requests seven scopes: reading Confluence page summaries and versions, searching Confluence, reading Confluence content permissions, reading Jira work items, its own storage, and personal data reporting. It requests no permission to write to Confluence or Jira.
- Your permissions, checked every time. Before any read or action the app checks, as the person asking, that they can view the Confluence page and edit the work item. The Rovo agent is held to the same checks.
- No credentials. The app never asks for a password or API token and holds no secrets. Forge supplies authentication at runtime.
- Careful logging. Logs carry identifiers, counts, status values and error codes. They never carry step notes, procedure text or account details.
- Validated input. Identifiers, step keys and notes are checked for shape and length before use, and all storage goes through Forge's typed storage interface, with no query built from user text.
What this app does not have
Runbooks for Confluence and Jira is maintained by one developer. It holds no SOC 2, ISO 27001 or similar certification, and it is not enrolled in the Marketplace bug bounty programme. How personal data is handled is set out in the privacy policy.