Security Policy

Last updated: August 31, 2026

This page describes the security practices for HelzBrand apps for Jira. It is separate from our Privacy Policy, which describes what data we collect and why.

Platform and hosting

HelzBrand apps are built on Atlassian Forge and run entirely on Atlassian's cloud infrastructure. We do not operate our own servers, databases, or hosting for app functionality. Application code executes in Forge's sandboxed runtime, and app data is stored in Forge hosted storage within the customer's Atlassian site trust boundary. Platform-level infrastructure security, network security, and physical security are provided by Atlassian; Atlassian's own certifications and practices are documented at atlassian.com/trust.

Data handling

Our apps follow a minimal data movement design. App data remains inside the customer's Jira site and Forge hosted storage. HelzBrand receives no customer data: there is no telemetry pipeline, no analytics collection, and no HelzBrand-operated endpoint that customer data is sent to. Where an app exists to integrate with a third-party service that the customer explicitly connects, data flows only between the customer's Jira site and that service, and the app's Marketplace listing describes exactly what is accessed and shared.

Encryption

Data in transit between the customer's browser, Jira, and Forge services is encrypted with TLS, enforced by the Forge platform. Data at rest in Forge hosted storage is encrypted by Atlassian's cloud infrastructure. Any credentials an integration app holds (such as an API token for a service the customer connects) are stored using Forge's secret storage facilities and are never written to logs or source code.

Access control and least privilege

Each app requests only the OAuth scopes required for its function, and scope requests are reviewed at every release. Read-only apps request no write scopes. Apps respect Jira's own permission model: users see only data their Jira permissions allow. HelzBrand developer console access is limited to the app developer and protected by strong authentication.

Development practices

All app code is version controlled with change history. Dependencies are audited for known vulnerabilities before each release, and releases are blocked on unresolved production dependency vulnerabilities. Secrets are never committed to source control. Apps are tested against a dedicated development site before any release is promoted to production, and Forge's staged environments (development, staging, production) separate test code from what customers run.

Vulnerability management and reporting

We monitor Atlassian security advisories and dependency vulnerability disclosures that affect our apps. If you believe you have found a security vulnerability in a HelzBrand app, please report it to security@helzbrand.com. We will acknowledge reports within three business days, keep you informed as we investigate, and ask that you practice coordinated disclosure: give us reasonable time to remediate before public disclosure. We do not take legal action against good-faith security research.

Incident response

If a security incident affecting customer data is confirmed, we will notify affected customers through the Marketplace listing contact channels and Atlassian's required processes without undue delay, describing what happened, what data was affected, and what remediation has been taken.

Certifications

HelzBrand does not currently hold independent security certifications. Our apps run entirely on Atlassian's certified cloud infrastructure; Atlassian's compliance programs (including SOC 2 and ISO 27001) are documented at atlassian.com/trust/compliance. This page will be updated if our certification status changes.

Contact

Security questions and reports: security@helzbrand.com