Back

Security and Privacy
at
Move Work Forward

Our 100% security guarantee for our customers and solutions

Join 7,500+ organizations in improving team transparency and productivity. Let's Move Work Forward together.

Security is a top priority

Data Privacy

We prioritize customer data privacy with GDPR-compliant data collection and processing.

SOC 2 Type II Certified
We ensure that our systems, processes, and controls meet specific trust service criteria.
Secure Development
We employ end to end vulnerability checks during our coding and development process.
Infrastructure Access
We use multi-factor authentication and restrict access based on team’s needs.
Learn more

Data Protection

Data At Rest

All datastores with customer data (only app configurations), in addition to S3 buckets, are encrypted at rest. Sensitive collections and tables also use row-level encryption.

This means the data is encrypted even before it hits the database so that neither physical access, nor logical access to the database, is enough to read the most sensitive information.

Data in transit

We use TLS 1.2 or higher everywhere data is transmitted over potentially insecure networks. We also use features such as HSTS (HTTP Strict Transport Security) to maximize the security of our data in transit. Server TLS keys and certificates are managed by AWS and deployed via Application Load Balancers.

Secret Management

Encryption keys are managed via AWS Key Management System (KMS). KMS stores key material in Hardware Security Modules (HSMs), which prevents direct access by any individuals, including employees of Amazon and Vanta. The keys stored in HSMs are used for encryption and decryption via Amazon’s KMS APIs.

Application secrets are encrypted and stored securely via AWS Secrets Manager and Parameter Store, and access to these values is strictly limited.

Security Monitored By Vanta.
View Our Trust report here

Our Cloud Fortified Apps

Microsoft Teams Confluence Connector Lite

Improve collaboration and enhance team transparency by integrating Confluence with Microsoft Teams.

Learn more

GitLab for Confluence

Unite your development and documentation with our GitLab Confluence integration: Collaborate smarter and deliver faster.

Learn more

Azure DevOps Confluence Connector

Transform Your Development Process with Azure DevOps and Confluence Integration.

Learn more

GitHub Links for Jira

Jira Github integration simplifies the development process and reduces the need for context switching.

Learn more

GitHub Links for Confluence

Our integration of Confluence and GitHub enhances documentation and establishes a connection between the two platforms.

Learn more

Advanced Microsoft Teams Jira Connector

Integrate Jira with Microsoft Teams to streamline communication & enhance collaboration between teams for efficient project management.

Learn more

Atlassian Security Program Guarantee

We participate in all the Atlassian marketplace security programs, so all of our products are extra safe.

Marketplace Bug Bounty Program

To get a Cloud Fortified or Cloud Security Participant badge, apps must participate in this program.

Ecoscanner
Atlassian’s Ecoscanner platform performs security checks across all Marketplace cloud apps on an ongoing basis.
Vulnerability Disclosure Program
Atlassian runs the program so marketplace partners can mitigate security risks
Cloud App Security Requirements
We participate here and meet Atlassian's mandatory requirements for app security
Security Bug Fix Policy
We adhere to security bug fix SLAs for all our apps listed on the Atlassian Marketplace.
Security Self Assessment Program
We participated in this program and have earned our cloud security badge for multiple apps as a result.

App Security In Our Development Process

We take our customers security seriously and take all the steps to delivered secure solutions even from the beginning of the development process.

Team members pull stories from the backlog as capacity allows. Typically their first step is to write tests to assert the behaviour we expect. From there they will write code to make tests pass, and then refactor as needed.

When a team member is ready for code review they add two of their colleagues to a pull request. Their colleagues review the code for consistency, sanity, and against the acceptance criteria of the user story.

During the code review process we begin user acceptance testing of the functionality in the host product. At this point we're trying to ensure that what we deliver makes sense from a customers perspective. This often turns up UI/UX improvements for the story which are then subsequently included in the pull request.

Once the pull request has been approved the development branch is merged into our master branch where we do final user acceptance testing before merging to release branch and releasing the packages.

Some of our use cases

Microsoft Teams integration for Jira Cloud, Server and Data Center.Microsoft Teams integration for Jira Cloud, Server and Data Center.Microsoft Teams integration for Jira Cloud, Server and Data Center.Microsoft Teams integration for Jira Cloud, Server and Data Center.
Atlassian Logo
Platinum Marketplace Partner
AICPA Logo
SOC 2 Type II Certified
Gitlab Logo
GitLab Official partner
EU GDPR Logo
EU GDPR Compliant
Google Logo
Google Partner
Microsoft Logo
Microsoft Partner