Security measures and reporting
No certification or Marketplace badge is claimed.
Working Day Guard for Jira runs on Atlassian Forge. The pre-release implementation declares report:personal-data, read:jira-work, write:jira-work and storage:app. The approved PDR scope supports bounded reporting to Atlassian without adding profile collection. It declares no external egress, webtrigger or remote application API. Forge provides platform hosting controls; these are not Rillnook Labs certifications.
Backend checks use trusted Forge context. Project settings require project administration; audit follows current-user issue visibility. App-context Jira access checks the relevant permissions, and writes are limited to Due date. Input dates/ranges, settings revisions and request schemas are validated. Tenant storage is installation-scoped, with explicit project boundaries.
Paid features require license.active=true. Invalid or unavailable entitlement fails safely. Signed data-response authorization and required PDR processing are separate and do not enable paid actions. Concurrent storage operations use conditional fences; uncertain Jira responses are not blindly replayed. Jira's final read-to-write interval is not atomic, and no absolute prevention of concurrent overwrites is promised.
We use dependency analysis, static quality checks and secret scanning. Known development-tool risks are assessed separately from deployed dependencies. No independent penetration test, bug bounty, SOC2, ISO27001 or other operator certification is represented as completed.
Report suspected vulnerabilities to security@rillnook.com. Include a minimal synthetic reproduction and potential impact. Do not test other customers, access unnecessary data or send credentials. This contact policy does not grant testing authorization. The owner triages and handles applicable Atlassian/customer notifications. Legal and incident duties are not limited by ordinary support hours; no 24/7 staffing or fixed resolution SLA is promised.