Security

I take the security of Aquarium Apps products seriously. If you've found a vulnerability, I want to hear about it.

Reporting

Email security@aquariumapps.io with:

  • The product and version affected
  • Steps to reproduce
  • The impact of the vulnerability

What to Expect

I will acknowledge your report within 5 business days and keep you in the loop as I work on a fix.

Responsible Disclosure

Please report privately and give me a chance to fix the issue before disclosing it publicly. When testing, avoid accessing, modifying, or deleting data beyond what's needed to demonstrate the vulnerability, and don't run tests that could degrade service (e.g. denial-of-service, spam, or social engineering) for other users. Acting in good faith and within these guidelines, I won't pursue legal action against you for your research.

Scope

This policy covers all Aquarium Apps products and this website.

Additional Policies

Atlassian Forge

Every Jira app I ship runs entirely on Atlassian Forge, inheriting Atlassian's security standards, practices and policies.

  • Encryption - Forge encrypts data in transit and at rest as part of Atlassian's platform. See atlassian.com/trust.
  • Hosting - App data is stored in Forge Storage and Forge SQL, a TiDB database that Atlassian hosts and manages.
  • Data Access - A Forge app can only reach the data of the Jira instance it's installed on through Atlassian's permissioned APIs.
  • Subprocessors - Atlassian is the primary subprocessor for everything these apps do. Some apps may add optional subprocessors for a specific integrations. See Jira Apps DPA for additional details per app.
  • Compliance - All Forge apps run on Atlassian's own certified infrastructure. See atlassian.com/trust for what Atlassian holds.
  • Account Security - MFA is required on every account with publish or admin access to these apps.
  • Data Retention - Uninstalling a Forge app removes all data from the respective Forge Storage and Forge SQL records.
  • Incident Response - I will acknowledge vulnerability reports within 5 business days (see above), and I notify affected customers without undue delay if a data breach affects any app.