Security policy
Last updated 29 September 2026
How our apps are built
- Every Clearlane app is built on Atlassian Forge and runs on Atlassian’s infrastructure (Runs on Atlassian). We operate no servers of our own.
- Authentication and authorisation are handled by Atlassian. Our apps act with the permissions of the person using them and cannot see anything that person cannot see.
- Apps request the smallest set of permissions they need. Clearlane Forecast and Clearlane Pulse only read Jira work; Clearlane Fresh reads Confluence pages and edit dates.
- No customer content is copied, sent or stored outside Atlassian. The only data we keep is Clearlane Fresh’s list of page confirmations, stored in Atlassian’s Forge storage for your site.
- Logs contain technical counters only (such as the number of work items processed), never customer content.
- We do not ask for passwords, API tokens or other secrets.
Reporting a vulnerability
Write to [email protected] with the app name, the steps to reproduce and the impact you observed. We acknowledge reports within two business days, keep you informed while we investigate, and fix confirmed issues as a priority. Please give us reasonable time to fix an issue before disclosing it publicly, and do not access or change data that is not yours.