Security Policy

Last Updated: September 2026

At BPMN, UML, Workflow Automation & Portfolio Manager, we take the security of your data seriously. Because our application integrates directly into your Jira environment, this policy outlines our commitment to security, our architectural footprint, and how data is handled.

Security Architecture Summary: BPMN, UML, Workflow Automation & Portfolio Manager is built exclusively on the Atlassian Forge serverless framework. This means your data never leaves the Atlassian cloud ecosystem to be processed or stored on independent, external infrastructure.

1. Data Storage & Isolation

2. Data Transit & Encryption

3. Infrastructure & Platform Security

By leveraging the Atlassian Forge platform, BPMN, UML, Workflow Automation & Portfolio Manager inherits Atlassian's robust, enterprise-grade security posture, including:

4. Application Permissions (Least Privilege)

The app requests only the minimum necessary permission scopes required to manage and display your portfolio data. These scopes are explicitly declared during installation, and the app cannot act outside of those boundaries or access data it is not authorized to see.

5. Access Control for App Content

Diagrams and automation rules created in the App are governed by your existing Jira project permissions:

6. Vulnerability Management

7. Reporting a Vulnerability

If you discover a potential security vulnerability in BPMN, UML, Workflow Automation & Portfolio Manager, please do not disclose it publicly. Report it directly to us by opening an issue on our GitHub repository or contacting us at: felixtrihardjo@gmail.com. We review all security reports promptly.