The app is built on Atlassian Forge and runs entirely on Atlassian's own infrastructure. We operate no server, no database and no network of our own for it. There is no host of ours for an attacker to reach, and no credential of ours that could be stolen to reach your site.
The app declares no Jira API scopes. It cannot read your work items, projects, users or attachments, because it was never granted the ability to. It reads and writes only its own configuration, through the interface Atlassian provides.
Inside your own Atlassian site, in the app's own configuration. It is covered by Atlassian's encryption in transit and at rest, their access controls and their retention rules. We never receive a copy.
There is none to manage. The app never asks for a password, an API token, a personal access token or any other shared secret, and it has nowhere to store one if it did.
Every release is deployed through the Forge CLI from a workstation with two-step verification on the Atlassian account. Dependencies are pinned in a lockfile. Only Atlassian's own review and deployment pipeline can put a version in front of your users.
Write to security@namubase.com with the words security report in the subject. Please include enough detail to reproduce the problem.
This is the order we work in.
One person runs this app, so there is no handover step and no rota to wake up. The contact above reaches that person.