Handover for Jira

Security Policy

Grey Line Interactive LLC, an Idaho limited liability company, Meridian, Idaho · Security contact: [email protected] · Effective date: September 12, 2026

Architecture: security by subtraction

Handover for Jira is built exclusively on Atlassian Forge and qualifies for Atlassian's Runs on Atlassian program. We operate no servers, no databases, and no third party services. All compute is Forge functions on Atlassian infrastructure, and the app makes zero network calls to any non Atlassian host: no telemetry, no analytics beacons, no external CDN, no AI APIs. The most common classes of app risk (vendor server compromise, data interception in transit to a vendor, vendor database breach) are not reduced here; they are structurally absent.

Data handling

Data read from your Jira site is processed inside Forge and stored minimally in Forge storage attached to your own site. Data residency follows your Jira site automatically. The app stores:

DataWhereRetention
Offboarding plans (leaver and successor account IDs, item list)Forge storage on your siteUntil deleted in app, or app uninstall
Execution progressForge storage on your siteUntil app uninstall
Audit recordsForge storage on your siteUntil deleted in app, or app uninstall
Settings (comment template)Forge storage on your siteUntil app uninstall

Stored fields are Atlassian account IDs, display names, issue keys and one line issue summaries: identifiers and titles already visible in your Jira. The app stores no email addresses, no credentials, no issue descriptions, comments or attachments, and nothing about users who are not part of an offboarding. Admins can permanently delete any offboarding record from inside the app. Uninstalling removes the app's storage under Atlassian's data lifecycle.

Encryption

All traffic between your browser, Jira, and the app's Forge backend is carried over Atlassian's infrastructure using TLS 1.2 or higher. Data at rest in Forge storage is encrypted by Atlassian's platform controls. Because the app has no infrastructure of its own, there are no vendor managed keys, certificates, or endpoints to audit separately: the encryption posture is Atlassian's, documented in Atlassian's own trust and compliance program.

Access control

Permissions (OAuth scopes), least privilege

ScopeWhy
read:jira-userUser search (leaver, successors) and the group membership snapshot
read:jira-workIssue, filter and dashboard inventory
write:jira-workIssue reassignment, comments, filter and dashboard ownership transfer
manage:jira-projectProject lead and component lead changes
manage:jira-configurationAdmin level inventory reads Jira requires
read:dashboard:jira, write:dashboard:jira, read:group:jira, write:group:jiraGranular equivalents declared up front so future Atlassian API changes never force a surprise permission re-approval
storage:appPlans, progress and audit history in Forge storage

Scopes are declared up front and stable: app updates do not request new permissions.

Vulnerability management

Certifications

Grey Line Interactive LLC does not hold independent certifications such as SOC 2 or ISO 27001. The app runs entirely inside Atlassian's cloud, so the hosting, storage and network layers are covered by Atlassian's own compliance program (see Atlassian's Trust Center for their current certifications). We state this plainly rather than borrowing badges: the honest security claim of this app is that your data never leaves the Atlassian infrastructure you have already assessed.

Reporting a vulnerability

Email [email protected]. We acknowledge within 2 business days. Please include reproduction steps. We support coordinated disclosure and will credit reporters in release notes unless anonymity is requested.