Security

Notes for Jira Dashboards · sellerkit · Version 1.0, effective 4 September 2026

Where the app runs

The app is built on Atlassian Forge and runs entirely on Atlassian's own infrastructure. We operate no server, no database and no network of our own for it. There is no host of ours for an attacker to reach, and no credential of ours that could be stolen to reach your site.

Permissions

The app declares no Jira API scopes. It cannot read your work items, projects, users or attachments, because it was never granted the ability to. It reads and writes only its own configuration, through the interface Atlassian provides.

Where your content is kept

Inside your own Atlassian site, in the app's own configuration. It is covered by Atlassian's encryption in transit and at rest, their access controls and their retention rules. We never receive a copy.

Authentication

There is none to manage. The app never asks for a password, an API token, a personal access token or any other shared secret, and it has nowhere to store one if it did.

Building and releasing

Every release is deployed through the Forge CLI from a workstation with two-step verification on the Atlassian account. Dependencies are pinned in a lockfile. Only Atlassian's own review and deployment pipeline can put a version in front of your users.

Reporting a vulnerability

Write to globalmatchhub@gmail.com with the words security report in the subject. Please include enough detail to reproduce the problem.

If something happens

If a problem turns out to affect users, we fix it, ship it, and say so on this page and in the release notes with what happened and what to do about it.

Contact

globalmatchhub@gmail.com