Security

Filter List for Jira Dashboards · sellerkit · Version 1.0, effective 4 September 2026

Where the app runs

The app is built on Atlassian Forge and runs entirely on Atlassian's own infrastructure. We operate no server, no database and no network of our own for it. There is no host of ours for an attacker to reach, and no credential of ours that could be stolen to reach your site.

Permissions

The app declares one Jira scope, read:jira-work, and nothing else. It can read work items and saved filters; it cannot write anything, cannot touch project or user administration, and cannot reach attachments.

Every read runs as the person looking at the dashboard, not as an administrator and not as us. Someone who cannot open a project in Jira cannot see its numbers through this gadget either.

Where your content is kept

Inside your own Atlassian site, in the app's own configuration. It is covered by Atlassian's encryption in transit and at rest, their access controls and their retention rules. We never receive a copy.

Authentication

There is none to manage. The app never asks for a password, an API token, a personal access token or any other shared secret, and it has nowhere to store one if it did.

Building and releasing

Every release is deployed through the Forge CLI from a workstation with two-step verification on the Atlassian account. Dependencies are pinned in a lockfile. Only Atlassian's own review and deployment pipeline can put a version in front of your users.

Reporting a vulnerability

Write to security@namubase.com with the words security report in the subject. Please include enough detail to reproduce the problem.

If the link does not open in your client, the address is security@namubase.com.

If something happens

This is the order we work in.

  1. Contain. If a released version is the cause, we pull or roll it back first, before writing anything else down.
  2. Tell Atlassian within 24 hours of finding it, as a P1 ticket in the Marketplace Partner service desk, and keep them updated at least every 6 hours until it is closed.
  3. Tell affected administrators within 72 hours of confirming it, by the email on their Marketplace account: what happened, what data was involved, what we have done, and what they should do.
  4. Fix within the Marketplace deadlines for the severity: 10 days for critical, 4 weeks for high, 12 weeks for medium, 25 weeks for low.
  5. Write it up on this page and in the release notes, including the cause and what stops it happening again.

One person runs this app, so there is no handover step and no rota to wake up. The contact above reaches that person.

Contact

security@namubase.com