Security Policy

Visual Progress Tracker for Jira ยท Last updated: October 5, 2026

1. Overview

Visual Progress Tracker for Jira ("the App") is built on the Atlassian Forge platform and operates entirely within Atlassian's infrastructure under the Runs on Atlassian trust boundary. Its dashboard gadgets and widgets read Jira with the permissions of the person viewing them, its only change to Jira is writing progress values into the App's own custom fields, it makes no outbound network calls to any external server, and it stores no credentials of any kind. This document describes the App's security architecture and our practices.

2. Architecture & Runtime Environment

3. Access Control

ControlDetails
Viewer's own permissions The dashboard gadgets and widgets search work items, subtasks and epics as the user (Forge asUser), and the project picker and the progress details on a work item read Jira the same way. Jira applies that person's permissions, so each viewer sees only what Jira allows them to see.
Cache per viewer Results of the gadgets and widgets are cached under the viewer's account ID, so a cached result is only ever shown to the person whose search produced it. A JQL filter appears in the cache key only as a hash.
App account for the progress fields The status and subtask progress fields are computed with the App's own account (asApp) when Jira asks for their value, reading only the statuses of that work item and its subtasks. "Recalculate All Fields" runs only after Jira confirms, as the person starting it, that they may browse the project; it writes with the App's account and only into the App's own progress fields, at most once every 7 days.
Minimal API scopes read:jira-work (work items, projects, fields), write:jira-work (only to write progress values into the App's own custom fields), storage:app (settings, the per-viewer cache, technical records and anonymous usage counters). Three scopes, no admin scopes.
Admin settings for Jira administrators only The status-to-progress mapping and the color thresholds can be changed only after Jira confirms, at that moment and as the person saving, that they are a Jira administrator.
Input validation Project keys are checked against a strict character set before they are used in a JQL query. JQL filters entered in the gadget settings run with the viewer's own permissions and are never stored by the App or written to its logs, only a hash of them.
Developer access None. We cannot read, access, or export any data stored in your Jira instance or in the App's Forge storage. All data resides within Atlassian's infrastructure.

4. Data Protection

Data in transit:

Data at rest:

Technical logs:

Data minimization:

5. No External Credentials or Integrations

The App does not require or accept any API keys, tokens, passwords, or third-party credentials. There is no configuration that could expose user secrets, and there are no integrations beyond the Atlassian platform itself.

6. Dependency & Vulnerability Management

7. Incident Response

If a security issue is discovered in the App:

To report a security vulnerability, contact support@janekbehrens.de with the subject line "Security Report โ€” Visual Progress Tracker". We aim to acknowledge reports within 2 business days.

8. Organizational Security Controls

9. Compliance

10. What We Cannot Access

For complete transparency, we have no technical means to access:

11. Contact

For security questions or to report a vulnerability:
Email: support@janekbehrens.de
Subject: Security Report โ€” Visual Progress Tracker

Atlassian and Jira are trademarks of Atlassian. Visual Progress Tracker for Jira is an independent app by Janek Behrens and is not made or endorsed by Atlassian; the product names only say which products the app works with.