Security Policy
Last updated: August 31, 2026
This page describes the security practices for HelzBrand apps for Jira. It is separate from our Privacy Policy, which describes what data we collect and why.
Platform and hosting
HelzBrand apps are built on Atlassian Forge and run entirely on Atlassian's cloud infrastructure. We do not operate our own servers, databases, or hosting for app functionality. Application code executes in Forge's sandboxed runtime, and app data is stored in Forge hosted storage within the customer's Atlassian site trust boundary. Platform-level infrastructure security, network security, and physical security are provided by Atlassian; Atlassian's own certifications and practices are documented at atlassian.com/trust.
Data handling
Our apps follow a minimal data movement design. App data remains inside the customer's Jira site and Forge hosted storage. HelzBrand receives no customer data: there is no telemetry pipeline, no analytics collection, and no HelzBrand-operated endpoint that customer data is sent to. Where an app exists to integrate with a third-party service that the customer explicitly connects, data flows only between the customer's Jira site and that service, and the app's Marketplace listing describes exactly what is accessed and shared.
Encryption
Data in transit between the customer's browser, Jira, and Forge services is encrypted with TLS, enforced by the Forge platform. Data at rest in Forge hosted storage is encrypted by Atlassian's cloud infrastructure. Any credentials an integration app holds (such as an API token for a service the customer connects) are stored using Forge's secret storage facilities and are never written to logs or source code.
Access control and least privilege
Each app requests only the OAuth scopes required for its function, and scope requests are reviewed at every release. Read-only apps request no write scopes. Apps respect Jira's own permission model: users see only data their Jira permissions allow. HelzBrand developer console access is limited to the app developer and protected by strong authentication.
Development practices
All app code is version controlled with change history. Dependencies are audited for known vulnerabilities before each release, and releases are blocked on unresolved production dependency vulnerabilities. Secrets are never committed to source control. Apps are tested against a dedicated development site before any release is promoted to production, and Forge's staged environments (development, staging, production) separate test code from what customers run.
Vulnerability management and reporting
We monitor Atlassian security advisories and dependency vulnerability disclosures that affect our apps. If you believe you have found a security vulnerability in a HelzBrand app, please report it to security@helzbrand.com. We will acknowledge reports within three business days, keep you informed as we investigate, and ask that you practice coordinated disclosure: give us reasonable time to remediate before public disclosure. We do not take legal action against good-faith security research.
Incident response
If a security incident affecting customer data is confirmed, we will notify affected customers through the Marketplace listing contact channels and Atlassian's required processes without undue delay, describing what happened, what data was affected, and what remediation has been taken.
Certifications
HelzBrand does not currently hold independent security certifications. Our apps run entirely on Atlassian's certified cloud infrastructure; Atlassian's compliance programs (including SOC 2 and ISO 27001) are documented at atlassian.com/trust/compliance. This page will be updated if our certification status changes.
Contact
Security questions and reports: security@helzbrand.com
Helz