Design commitments
The app never sends a Jira mutation request.
Jira workflow configuration stays within Atlassian services.
No issue, comment, attachment, user-email, or customer-file scopes.
Installation-scoped Forge storage with hard record and byte limits.
No prompt injection surface and no customer data sent to an AI model.
Production checks reject inactive or missing licenses.
Requested permissions
Data flow
No separate application server, database, analytics SDK, advertising SDK, or generative-AI provider participates in this path.
Operational safeguards
- Retry limits and bounded pagination prevent unbounded API use.
- Last-known-good results remain available after ordinary Jira API failures.
- Public errors are classified without returning raw Jira response bodies.
- The release gate covers static analysis, type checking, manifest validation, deterministic tests, and dependency auditing.
Report a vulnerability
Email security@workflowlinter.com. Include the app version, affected Jira Cloud URL with tenant-specific details removed where possible, reproduction steps, impact, and diagnostics output. Do not include credentials, API tokens, or sensitive issue content.
We acknowledge security reports within two business days and prioritize remediation based on verified impact.