Security Policy for qadram Atlassian Marketplace Apps
This Security Policy describes the security practices applied by BranchCreation S.L.U., operating under the brand qadram ("we", "us", or "our") to applications published through the Atlassian Marketplace.
1. Security Approach
We design and maintain our Atlassian Marketplace applications with the objective of protecting customer information and following Atlassian's security requirements for Marketplace Cloud applications.
Our Cloud applications covered by this policy are built using the Atlassian Forge platform unless otherwise stated in the individual Marketplace listing.
Forge operates under a shared responsibility security model between Atlassian and application developers.
2. Hosting and Infrastructure
Forge applications run on infrastructure operated and secured by Atlassian.
For Forge applications covered by this policy, we do not maintain separate application servers or externally accessible backend infrastructure unless explicitly disclosed in the application's Marketplace listing.
Atlassian is responsible for operating and securing the underlying Forge infrastructure.
3. Authentication and Authorization
User authentication is provided by Atlassian.
Our applications do not collect or store Atlassian user passwords.
Applications request only the permissions and OAuth scopes necessary to provide their intended functionality.
When accessing Atlassian APIs, applications use the authentication and authorization mechanisms provided by the Atlassian Forge platform.
Application functionality is designed to respect the permissions available to the relevant user or application context.
4. Data Protection
Where application data must be stored persistently, Forge-hosted storage may be used.
Data stored within Forge-hosted storage benefits from the encryption-at-rest and infrastructure security mechanisms provided by Atlassian.
Communication with Atlassian services is performed through secure mechanisms provided by the Forge platform.
We do not intentionally transmit Atlassian End User Data to external services unless such transfers are necessary for a specific application's functionality and are clearly disclosed.
5. Tenant Isolation
Our applications are designed to prevent data belonging to one Atlassian customer from being exposed to another customer.
Where tenant-specific data is processed or stored, it is kept logically isolated using the mechanisms and application-development practices provided or recommended by Atlassian Forge.
We do not intentionally store tenant-specific information in shared application state in a manner that could expose it to another tenant.
6. Secrets and Credentials
Our applications do not embed customer passwords, API tokens, or authentication credentials in application source code.
Where application secrets are required, they are managed using appropriate secure mechanisms provided by Atlassian Forge.
Credentials and security-sensitive information are never intentionally exposed through application user interfaces or logs.
7. Logging and Monitoring
We may use application logs provided through the Forge platform for:
- Application diagnostics.
- Troubleshooting.
- Operational monitoring.
- Detection and investigation of security issues.
We design our applications to avoid intentionally logging:
- Passwords.
- Authentication tokens.
- API secrets.
- Sensitive personal information.
- Unnecessary customer-generated content.
8. Vulnerability Management
We review and maintain our applications to address identified security vulnerabilities.
When a security vulnerability affecting one of our applications is identified, we assess its severity and take appropriate remediation measures.
We aim to resolve vulnerabilities within the applicable timeframes established by Atlassian's security requirements and Security Bug Fix Policy for Marketplace applications.
9. Dependency Security
Third-party software dependencies used by our applications are kept to the minimum reasonably necessary.
We periodically review and update dependencies when security fixes or relevant updates become available.
Known vulnerabilities affecting dependencies are evaluated and remediated according to their severity and potential impact.
10. Secure Development Practices
Our development practices include, where applicable:
- Reviewing requested Atlassian scopes and permissions.
- Applying least-privilege principles.
- Reviewing application code before releases.
- Avoiding unnecessary collection or storage of customer data.
- Protecting secrets and credentials.
- Keeping dependencies updated.
- Addressing identified security vulnerabilities.
- Following Atlassian Forge and Marketplace security guidance.
11. Data Residency
Where an application uses only Atlassian Forge-hosted capabilities eligible for Atlassian data residency, data residency is governed by the capabilities and configuration provided by the Forge platform.
Any specific data residency support applicable to an individual application will be declared in its Atlassian Marketplace Privacy & Security information.
12. External Services
Our Forge applications do not transmit customer data to external services unless expressly required for the functionality of a particular application.
If an application uses external services or remote infrastructure, this will be disclosed in the relevant Marketplace documentation and Privacy & Security information.
13. Security Incidents
If we become aware of a security incident affecting customer data or the security of one of our applications, we will investigate the incident and take appropriate remediation measures.
Where legally or contractually required, affected customers and/or Atlassian will be notified in accordance with applicable requirements.
14. Responsible Disclosure
Security researchers or customers who believe they have identified a security issue affecting one of our Atlassian Marketplace applications are encouraged to report it to us.
Please include sufficient information to reproduce and investigate the issue.
Security reports should be sent to:
qadram (BranchCreation S.L.U.)
Email: info@qadram.com
We request that security issues are not publicly disclosed before we have had a reasonable opportunity to investigate and remediate them.
15. Policy Updates
We may update this Security Policy as our applications, infrastructure, security practices, or Atlassian requirements change.
The latest version will always be made available at this location.
16. Contact
For security-related questions regarding our Atlassian Marketplace applications, please contact:
qadram (BranchCreation S.L.U.)
Website: https://qadram.com
Email: info@qadram.com