Security
A concise overview of the security architecture and data boundaries for Shurivo for Jira Service Management.
Architecture
- The App runs on Atlassian Forge.
- No Forge Remote is used.
- No Shurivo-operated runtime server is used.
- No external customer-data database is used.
- No third-party analytics or telemetry SDK is used for App runtime customer data.
Data boundaries
Jira/Jira Service Management request data is read only as needed to provide the App’s configured functionality. Approved field changes and audit information are written inside Jira. Project-level App configuration is stored in Atlassian Forge KVS.
Request contents and request before/after values are not stored in Forge KVS.
Authorization and access control
The App performs authorization and configured policy checks before supported request edits. These checks may use Jira permission information, requester identity, request participants, request status, request type, project configuration, and configured actor/status rules.
Logging
The App does not intentionally log customer request content, Atlassian account IDs, or request before/after values. Operational logs are limited to information needed to operate and troubleshoot the App.
Transport and platform security
Because the App runs on Atlassian Forge, core platform hosting, tenant isolation, encryption, and supported transport controls are provided through Atlassian’s Forge platform. Shurivo is responsible for the security of the App code, configuration, permissions, dependencies, and operational practices within that shared-responsibility model.
Vulnerability management
Security issues affecting the App are triaged and remediated according to their severity and applicable Atlassian Marketplace requirements. Shurivo also follows Atlassian’s Marketplace security incident and vulnerability-management processes where applicable.
Report a vulnerability
Please report suspected security vulnerabilities to security@shurivo.com. Include enough detail to reproduce or assess the issue, but do not send unnecessary customer data or secrets.
Certifications
Shurivo does not claim an independent SOC 2, ISO 27001, FedRAMP, or HIPAA certification.
Contact
Security: security@shurivo.com
Privacy: privacy@shurivo.com
Support: support@shurivo.com