StoryScale legal
Security Policy
Last updated: June 19, 2026.
Security reporting and incident handling
We welcome responsible disclosure of security issues. Report vulnerabilities to [email protected].
- Initial acknowledgment target: within 3 business days.
- We triage reported issues by severity and impact.
- We prioritize remediation based on risk to customer data and service continuity.
- When applicable, we coordinate customer communications for material incidents.
Vulnerability management process
- Dependency updates and patching are part of regular maintenance cycles.
- Code changes are reviewed before release.
- Build and validation checks are executed in CI before merge and release.
- Security issues are tracked from report to remediation and verification.
Technical and organizational controls
- Forge-hosted app architecture and Atlassian authentication model.
- Least-privilege permission scopes aligned to app functionality.
- Controlled write-back behavior to Jira fields (explicit publish action).
- Environment-level access control for code repositories and deployment workflows.
- Transport security via HTTPS for web traffic and API communication.
- Operational logging and monitoring for troubleshooting and reliability.
Customer responsibilities
Customers are responsible for their Atlassian tenant configuration, user access governance, and Jira project permissions.
Contact
Security contact: [email protected]
