Handover for Jira is built exclusively on Atlassian Forge and qualifies for Atlassian's Runs on Atlassian program. We operate no servers, no databases, and no third party services. All compute is Forge functions on Atlassian infrastructure, and the app makes zero network calls to any non Atlassian host: no telemetry, no analytics beacons, no external CDN, no AI APIs. The most common classes of app risk (vendor server compromise, data interception in transit to a vendor, vendor database breach) are not reduced here; they are structurally absent.
Data read from your Jira site is processed inside Forge and stored minimally in Forge storage attached to your own site. Data residency follows your Jira site automatically. The app stores:
| Data | Where | Retention |
|---|---|---|
| Offboarding plans (leaver and successor account IDs, item list) | Forge storage on your site | Until deleted in app, or app uninstall |
| Execution progress | Forge storage on your site | Until app uninstall |
| Audit records | Forge storage on your site | Until deleted in app, or app uninstall |
| Settings (comment template) | Forge storage on your site | Until app uninstall |
Stored fields are Atlassian account IDs, display names, issue keys and one line issue summaries: identifiers and titles already visible in your Jira. The app stores no email addresses, no credentials, no issue descriptions, comments or attachments, and nothing about users who are not part of an offboarding. Admins can permanently delete any offboarding record from inside the app. Uninstalling removes the app's storage under Atlassian's data lifecycle.
All traffic between your browser, Jira, and the app's Forge backend is carried over Atlassian's infrastructure using TLS 1.2 or higher. Data at rest in Forge storage is encrypted by Atlassian's platform controls. Because the app has no infrastructure of its own, there are no vendor managed keys, certificates, or endpoints to audit separately: the encryption posture is Atlassian's, documented in Atlassian's own trust and compliance program.
| Scope | Why |
|---|---|
read:jira-user | User search (leaver, successors) and the group membership snapshot |
read:jira-work | Issue, filter and dashboard inventory |
write:jira-work | Issue reassignment, comments, filter and dashboard ownership transfer |
manage:jira-project | Project lead and component lead changes |
manage:jira-configuration | Admin level inventory reads Jira requires |
read:dashboard:jira, write:dashboard:jira, read:group:jira, write:group:jira | Granular equivalents declared up front so future Atlassian API changes never force a surprise permission re-approval |
storage:app | Plans, progress and audit history in Forge storage |
Scopes are declared up front and stable: app updates do not request new permissions.
Grey Line Interactive LLC does not hold independent certifications such as SOC 2 or ISO 27001. The app runs entirely inside Atlassian's cloud, so the hosting, storage and network layers are covered by Atlassian's own compliance program (see Atlassian's Trust Center for their current certifications). We state this plainly rather than borrowing badges: the honest security claim of this app is that your data never leaves the Atlassian infrastructure you have already assessed.
Email [email protected]. We acknowledge within 2 business days. Please include reproduction steps. We support coordinated disclosure and will credit reporters in release notes unless anonymity is requested.