The app is built on Atlassian Forge and runs entirely on Atlassian's own infrastructure. We operate no server, no database and no network of our own for it. There is no host of ours for an attacker to reach, and no credential of ours that could be stolen to reach your site.
The app declares one Jira scope, read:jira-work, and nothing else.
It can read work items and saved filters; it cannot write anything, cannot touch
project or user administration, and cannot reach attachments.
Every read runs as the person looking at the dashboard, not as an administrator and not as us. Someone who cannot open a project in Jira cannot see its numbers through this gadget either.
Inside your own Atlassian site, in the app's own configuration. It is covered by Atlassian's encryption in transit and at rest, their access controls and their retention rules. We never receive a copy.
There is none to manage. The app never asks for a password, an API token, a personal access token or any other shared secret, and it has nowhere to store one if it did.
Every release is deployed through the Forge CLI from a workstation with two-step verification on the Atlassian account. Dependencies are pinned in a lockfile. Only Atlassian's own review and deployment pipeline can put a version in front of your users.
Write to security@namubase.com with the words security report in the subject. Please include enough detail to reproduce the problem.
This is the order we work in.
One person runs this app, so there is no handover step and no rota to wake up. The contact above reaches that person.