Admin Settings
Data & Security Settings
Data Storage
The app stores all data using Atlassian Forge Key-Value Storage (KVS):
- All app data (time logs, report configurations, templates, portfolio filters, scoring data) is stored in Forge KVS
- Forge KVS is encrypted at rest and isolated per Jira installation
- No data is exported to or stored on Clovity's servers
- Data processing happens within the Atlassian platform boundary
What Data the App Accesses
| Data Type | Used For | Where Stored |
|---|---|---|
| Jira issues and projects | Capacity analysis, backlog scoring, portfolio views | Read from Jira; not copied |
| Jira worklogs | Time tracking - read and write | Written to Jira; time log metadata in Forge KVS |
| Jira users and groups | Assignee display, RBAC | Read from Jira; not copied |
| Jira configuration | Issue types, statuses, priorities, custom fields | Read from Jira; not copied |
| App configurations | Report setups, templates, portfolios, scoring | Stored in Forge KVS |
What the App Does NOT Access
- Confluence data
- Jira attachments and file content
- External services or third-party systems
- Any data outside your Jira Cloud instance
What the App Does NOT Do
- Does not transmit Jira data to Clovity's servers
- Does not store your data in any database outside the Atlassian platform
- Does not access Confluence, email, or any system outside your Jira Cloud instance
- Does not send data to third-party analytics or advertising platforms
Atlassian Forge Security
| Control | Details |
|---|---|
| Data Isolation | Each Jira installation has its own isolated Forge KVS namespace - no data sharing between tenants |
| Encryption at Rest | All Forge KVS data is encrypted by Atlassian |
| Encryption in Transit | All communication uses TLS 1.2+ |
| No External Data Egress | The app does not make outbound calls to Clovity servers |
| Access Control | App can only access Jira data permitted by the user's Jira permissions |
GDPR Compliance
The app processes personal data (Jira usernames, display names, email addresses) only as necessary for the app's functionality:
- Processed on the Atlassian platform within your chosen data residency region
- Not shared with Clovity or any third party
- Subject to Atlassian's GDPR Data Processing Agreement (DPA) as the data processor
To exercise GDPR rights (access, deletion, portability) for data in Jira, contact your Jira site administrator. For data stored in Forge KVS by this app, contact developers@clovity.com.
Compliance
- SOC 2 Type II (Atlassian platform level)
- ISO 27001 (Atlassian platform)
- GDPR compliance through Atlassian's data residency program
Security Contact
Report security vulnerabilities: developers@clovity.com Subject line: Security: [Brief description] Response within 1 business day.