At BPMN, UML, Workflow Automation & Portfolio Manager, we take the security of your data seriously. Because our application integrates directly into your Jira environment, this policy outlines our commitment to security, our architectural footprint, and how data is handled.
Security Architecture Summary: BPMN, UML, Workflow Automation & Portfolio Manager is built exclusively on the Atlassian Forge serverless framework. This means your data never leaves the Atlassian cloud ecosystem to be processed or stored on independent, external infrastructure.
1. Data Storage & Isolation
No External Databases: We do not operate external servers, databases, or cloud storage systems. All application state, configuration, and user-authored content is stored within Atlassian's secure storage systems (Forge Storage API).
What Is Persisted: Content you author in the App is saved so it survives between sessions. This includes BPMN and UML diagram definitions, their version history (version names, timestamps, optional commit messages, and the account ID of whoever saved each version), and any automation rules you configure. All of it resides in Forge Storage inside your Atlassian site.
Jira Data Is Not Duplicated: Your Jira issue data, portfolio structures, and user metrics are read on demand and processed in real time within the user's web browser or via Atlassian's compute infrastructure. We do not copy or persist your Jira content onto any infrastructure owned or controlled by us.
2. Data Transit & Encryption
Encryption in Transit: All communications between your browser, the app components, and the Jira REST APIs are encrypted using industry-standard Transport Layer Security (TLS 1.2 or higher) provided natively by Atlassian.
No External Egress: The application does not send data to any third-party analytics, tracking, or external APIs. Diagram rendering is performed entirely client-side within your browser — no diagram content is transmitted to an external rendering service. Your data remains strictly inside your Atlassian site.
3. Infrastructure & Platform Security
By leveraging the Atlassian Forge platform, BPMN, UML, Workflow Automation & Portfolio Manager inherits Atlassian's robust, enterprise-grade security posture, including:
Compute Isolation: App code runs in isolated, secure multi-tenant environments managed directly by Atlassian.
Storage Isolation: Forge Storage is scoped per-installation, so content saved on one Atlassian site is not reachable from any other.
Authentication & Authorization: The app relies entirely on Atlassian's Identity and Access Management (IAM). We never see, collect, or store user passwords or authentication tokens.
4. Application Permissions (Least Privilege)
The app requests only the minimum necessary permission scopes required to manage and display your portfolio data. These scopes are explicitly declared during installation, and the app cannot act outside of those boundaries or access data it is not authorized to see.
5. Access Control for App Content
Diagrams and automation rules created in the App are governed by your existing Jira project permissions:
Server-Side Permission Checks: Every save, revert, and delete operation re-validates the acting user's edit permission on the associated Jira project on the backend. Client-side controls are a convenience, never the enforcement boundary.
Read vs. Write Separation: Users without edit permission on a project see its diagrams in a read-only view with editing controls removed.
Concurrent Edit Protection: Saves are version-checked to prevent one user from silently overwriting another's work; conflicting edits surface a warning rather than discarding changes.
Append-Only History: Reverting a diagram creates a new version rather than deleting past ones, preserving a complete and auditable change trail.
6. Vulnerability Management
Dependency Scanning: We routinely audit and scan the open-source software dependencies used in our code package for known security vulnerabilities.
Automated Test Coverage: Backend permission and version-control logic is covered by an automated test suite that runs before each release.
Prompt Patching: Critical security patches or dependency updates are deployed immediately to ensure the app code remains secure.
7. Reporting a Vulnerability
If you discover a potential security vulnerability in BPMN, UML, Workflow Automation & Portfolio Manager, please do not disclose it publicly. Report it directly to us by opening an issue on our GitHub repository or contacting us at: felixtrihardjo@gmail.com. We review all security reports promptly.