Security

ArtUp Trace for Jira Cloud · Last updated: 2026-09-25

In short: ArtUp Trace is an Atlassian Forge app with the "Runs on Atlassian" designation. There are no ArtUp Labs servers in the path, no outbound network calls, and no third-party trackers. The App reads Jira as the current user, checks Jira permissions on every action, and never writes to your issues.

1. Architecture

ArtUp Trace is built entirely on Atlassian Forge and carries Atlassian's "Runs on Atlassian" designation. This means:

See the Privacy Policy for the full list of what is stored.

2. Access scopes and permissions

The App follows the principle of least privilege. It requests only the Atlassian scopes it needs, and nothing more:

Requested Atlassian scopes
ScopeUsed for
read:jira-workRead issues, issue links and project data needed to compute coverage and detect suspect links.
read:jira-userRead basic user information needed to show who confirmed a link.
storage:appStore the App's own settings, requirement/link records and baselines in Forge storage.

The App requests no write scopes for Jira issues. It reads Jira data as the current user, so it can only see what that user is already permitted to see in your Jira site, and it never writes to Jira issues.

Beyond the scopes above, the App performs a Jira permission check on every user-facing action before it acts — for example before showing an issue's traceability data or before recording a link confirmation — so a user cannot use the App to see or affect anything their own Jira permissions would not already allow.

3. Application security controls

4. Dependency and supply-chain security

5. Account and workstation security

6. Reporting a vulnerability

If you believe you have found a security vulnerability in ArtUp Trace or on this website, please email security@artuplabs.com with:

Please do not include Jira content beyond what is strictly needed to demonstrate the issue, and do not test against customer sites you do not control. We will acknowledge your report within 24 hours and keep you updated as we investigate and fix it. We currently do not run a paid bug bounty programme.

7. Incident response

ArtUp Labs follows a written incident response plan for every Marketplace app, owned by the security contact below and reviewed at least once a year and after every incident.

7.1 What counts as an incident

7.2 Detection channels

7.3 Response steps

Incident response steps and target times
StepTarget timeAction
Acknowledge24 hoursConfirm receipt to the reporter; open an internal incident record (date, source, affected apps, versions).
Triage24 hoursRate severity (Critical / High / Medium / Low); decide whether customer data is affected.
Notify Atlassianwithin 24 hours of becoming aware of an incident affecting customersRaise a P1 ticket with Atlassian Marketplace Security and keep it updated until closed.
Containas soon as possibleRotate compromised credentials (Atlassian API tokens, Forge credentials, source control, DNS, email); revoke sessions; if needed, ship a version that disables the affected feature, or ask Atlassian to pause the app.
Fixwithin the Marketplace Security Bug Fix Policy due dates for the severityPatch, test, deploy to production, and confirm the fix with the reporter or Atlassian.
Notify customerswithin 72 hours of identification, when their data is affectedEmail the technical and billing contacts of affected installations: what happened, what data, what we did, and what they should do.
Closeafter the fix is verifiedWrite a short post-incident review: root cause, timeline, and what changes prevent a repeat.

7.4 Preventive controls

8. Contact

Security contact: security@artuplabs.com. For general questions, see our Support page. For what data is stored and how, see our Privacy Policy.