The app is built on Atlassian Forge and runs entirely on Atlassian's own infrastructure. We operate no server, no database and no network of our own for it. There is no host of ours for an attacker to reach, and no credential of ours that could be stolen to reach your site.
The app declares no Jira API scopes. It cannot read your work items, projects, users or attachments, because it was never granted the ability to. It reads and writes only its own configuration, through the interface Atlassian provides.
Inside your own Atlassian site, in the app's own configuration. It is covered by Atlassian's encryption in transit and at rest, their access controls and their retention rules. We never receive a copy.
There is none to manage. The app never asks for a password, an API token, a personal access token or any other shared secret, and it has nowhere to store one if it did.
Every release is deployed through the Forge CLI from a workstation with two-step verification on the Atlassian account. Dependencies are pinned in a lockfile. Only Atlassian's own review and deployment pipeline can put a version in front of your users.
Write to globalmatchhub@gmail.com with the words security report in the subject. Please include enough detail to reproduce the problem.
If a problem turns out to affect users, we fix it, ship it, and say so on this page and in the release notes with what happened and what to do about it.