Your data stays in your Atlassian site.
Every Clearlane app runs on Atlassian’s own infrastructure. We operate no servers, receive none of your content and use no other provider. Here are the questions security, privacy and purchasing teams ask, with straight answers.
Built so your data has nowhere else to go.
Clearlane apps are built on Atlassian Forge. The platform decides where code runs and where data is kept, and our apps make no call outside Atlassian.
Hosted by Atlassian
Code runs on Atlassian’s infrastructure (Runs on Atlassian). Atlassian signs in every user, so your single sign-on, two-step verification and user management apply unchanged.
Stored in your site
The records an app keeps, such as signatures, audit trails, CAPA records, budgets or test results, sit in Atlassian’s Forge storage for your site, encrypted at rest by Atlassian.
Data residency
If your Jira or Confluence is pinned to a region, Forge pins the apps’ stored data to the same region and moves it with your site (Atlassian documentation). The data in scope is listed in our privacy policy.
Least privilege
Each app asks only for the permissions its features use and acts as the person using it. The few tasks that run with the app’s own access, such as daily reminders, are listed in our security policy.
Electronic signatures
Signing passwords are kept only as a salted scrypt hash in Atlassian’s secret storage, never in clear text, and signing locks after repeated failures.
Nothing sensitive in logs
Logs hold technical counters only, such as the number of work items processed. We never ask for your passwords, API tokens or other secrets.
Atlassian may occasionally run processing outside your region; stored data stays pinned.
The questions vendor assessments ask, answered.
Copy these answers into your assessment. For anything else, send us your questionnaire and we will complete it.
| Question | Answer |
|---|---|
| Where is our data stored and processed? | In your Atlassian site, on Atlassian’s infrastructure (Forge). Clearlane has no servers and keeps no copy of your data. |
| Does any data leave Atlassian? | No. The apps make no network call outside Atlassian. Reminders go through Jira’s and Confluence’s own notifications. |
| Which subprocessors handle our data? | None for your Jira and Confluence content. Atlassian hosts the apps, handles Marketplace billing and runs our help center. This website is served by Cloudflare and sets no cookies. |
| Can Clearlane see our content? | No: it never reaches us. We receive only the licence details Atlassian shares with Marketplace partners, and what you choose to send to support. |
| Do you hold SOC 2 or ISO 27001? | Clearlane holds no certificate of its own. The apps keep data only inside Forge, so that data is covered by the controls Atlassian applies to its platform, such as AES-256 encryption at rest and TLS 1.2 or higher in transit (Atlassian documentation). |
| How are vulnerabilities managed? | Dependencies are audited before every release and a software bill of materials (CycloneDX SBOM) is kept for each release. Reported issues are acknowledged within two business days and fixed within the deadlines of Atlassian’s Security Bug Fix Policy for Marketplace apps, which gives 10 days for a critical issue. |
| How is each release checked? | Automated tests of every workflow at the real Forge limits, simultaneous users and large volumes; runs on a real Atlassian site; an access test with an account that has no rights; and a security review of the code. |
| What if there is a security incident? | If an incident affects your data, we report it to Atlassian and tell affected customers within 72 hours of becoming aware of it. |
| What happens when we uninstall an app? | Atlassian deletes the app’s stored data under its retention rules. Your pages, work items and comments stay. Export evidence files (PDF or CSV) first if you need them. |
| Do the apps use AI? | No app sends your content to an AI service. |
| Which personal data do the apps keep? | Only what a record needs, such as Atlassian account IDs and the names shown at signing, inside your site. Details per app are in our privacy policy. |
Validating an app for GxP or ISO 13485?
Our validation support maps 21 CFR Part 11 and ISO 13485 requirements to what the apps do and to what stays your responsibility, with ready-to-run OQ test scripts.
Clearlane apps are designed to help you meet these requirements. They are not certified: compliance comes from your validated system together with your procedures.
Bought like any Atlassian app.
Atlassian Marketplace
Free trial, quotes, invoices, payment, renewals and refunds are handled by Atlassian under the Marketplace terms.
Your Solution Partner
Your Atlassian Solution Partner can quote and buy Clearlane apps for you, like any Marketplace app.
Public documents
Our licence terms, privacy policy and security policy are public. Publisher: Clearlane, a sole proprietorship registered in France, under French law (legal notice).
An independent publisher, close to your work.
At Clearlane, we have one simple rule: understand your work before writing a single line of code. Every app starts from a real need, one that quality, security and project teams live with every day, and that the Jira and Confluence community has sometimes been asking about for years. It does one thing, and it does it well. After that, you tell us where to go next. Write to us: we read everything, and we’ll get back to you.
Questions, answered.
- Is a small publisher a risk for us?
- Clearlane is a small, independent publisher. That is why the apps are built so you never depend on us for your data: Atlassian hosts and runs them, your data stays in your site, and the quality apps export their records as PDF evidence files.
- Will you fill in our security questionnaire?
- Yes. Send it through our help center or to [email protected]. Most answers are on this page.
- Can the apps change our data?
- Only where a feature needs it, with the permissions of the person who asks. For example, Gantt writes start and due dates, and CAPA creates the work items of its actions. Every change an app can make is listed in our security policy.
- Where do we report a vulnerability?
- Choose “Report a security issue” in our help center, or write to [email protected]. Our security.txt file gives the same contact.
Questions from your security team?
We answer within two business days, in English, French or German.