Security Policy for qadram Atlassian Marketplace Apps

    This Security Policy describes the security practices applied by BranchCreation S.L.U., operating under the brand qadram ("we", "us", or "our") to applications published through the Atlassian Marketplace.

    1. Security Approach

    We design and maintain our Atlassian Marketplace applications with the objective of protecting customer information and following Atlassian's security requirements for Marketplace Cloud applications.

    Our Cloud applications covered by this policy are built using the Atlassian Forge platform unless otherwise stated in the individual Marketplace listing.

    Forge operates under a shared responsibility security model between Atlassian and application developers.

    2. Hosting and Infrastructure

    Forge applications run on infrastructure operated and secured by Atlassian.

    For Forge applications covered by this policy, we do not maintain separate application servers or externally accessible backend infrastructure unless explicitly disclosed in the application's Marketplace listing.

    Atlassian is responsible for operating and securing the underlying Forge infrastructure.

    3. Authentication and Authorization

    User authentication is provided by Atlassian.

    Our applications do not collect or store Atlassian user passwords.

    Applications request only the permissions and OAuth scopes necessary to provide their intended functionality.

    When accessing Atlassian APIs, applications use the authentication and authorization mechanisms provided by the Atlassian Forge platform.

    Application functionality is designed to respect the permissions available to the relevant user or application context.

    4. Data Protection

    Where application data must be stored persistently, Forge-hosted storage may be used.

    Data stored within Forge-hosted storage benefits from the encryption-at-rest and infrastructure security mechanisms provided by Atlassian.

    Communication with Atlassian services is performed through secure mechanisms provided by the Forge platform.

    We do not intentionally transmit Atlassian End User Data to external services unless such transfers are necessary for a specific application's functionality and are clearly disclosed.

    5. Tenant Isolation

    Our applications are designed to prevent data belonging to one Atlassian customer from being exposed to another customer.

    Where tenant-specific data is processed or stored, it is kept logically isolated using the mechanisms and application-development practices provided or recommended by Atlassian Forge.

    We do not intentionally store tenant-specific information in shared application state in a manner that could expose it to another tenant.

    6. Secrets and Credentials

    Our applications do not embed customer passwords, API tokens, or authentication credentials in application source code.

    Where application secrets are required, they are managed using appropriate secure mechanisms provided by Atlassian Forge.

    Credentials and security-sensitive information are never intentionally exposed through application user interfaces or logs.

    7. Logging and Monitoring

    We may use application logs provided through the Forge platform for:

    • Application diagnostics.
    • Troubleshooting.
    • Operational monitoring.
    • Detection and investigation of security issues.

    We design our applications to avoid intentionally logging:

    • Passwords.
    • Authentication tokens.
    • API secrets.
    • Sensitive personal information.
    • Unnecessary customer-generated content.

    8. Vulnerability Management

    We review and maintain our applications to address identified security vulnerabilities.

    When a security vulnerability affecting one of our applications is identified, we assess its severity and take appropriate remediation measures.

    We aim to resolve vulnerabilities within the applicable timeframes established by Atlassian's security requirements and Security Bug Fix Policy for Marketplace applications.

    9. Dependency Security

    Third-party software dependencies used by our applications are kept to the minimum reasonably necessary.

    We periodically review and update dependencies when security fixes or relevant updates become available.

    Known vulnerabilities affecting dependencies are evaluated and remediated according to their severity and potential impact.

    10. Secure Development Practices

    Our development practices include, where applicable:

    • Reviewing requested Atlassian scopes and permissions.
    • Applying least-privilege principles.
    • Reviewing application code before releases.
    • Avoiding unnecessary collection or storage of customer data.
    • Protecting secrets and credentials.
    • Keeping dependencies updated.
    • Addressing identified security vulnerabilities.
    • Following Atlassian Forge and Marketplace security guidance.

    11. Data Residency

    Where an application uses only Atlassian Forge-hosted capabilities eligible for Atlassian data residency, data residency is governed by the capabilities and configuration provided by the Forge platform.

    Any specific data residency support applicable to an individual application will be declared in its Atlassian Marketplace Privacy & Security information.

    12. External Services

    Our Forge applications do not transmit customer data to external services unless expressly required for the functionality of a particular application.

    If an application uses external services or remote infrastructure, this will be disclosed in the relevant Marketplace documentation and Privacy & Security information.

    13. Security Incidents

    If we become aware of a security incident affecting customer data or the security of one of our applications, we will investigate the incident and take appropriate remediation measures.

    Where legally or contractually required, affected customers and/or Atlassian will be notified in accordance with applicable requirements.

    14. Responsible Disclosure

    Security researchers or customers who believe they have identified a security issue affecting one of our Atlassian Marketplace applications are encouraged to report it to us.

    Please include sufficient information to reproduce and investigate the issue.

    Security reports should be sent to:

    qadram (BranchCreation S.L.U.)

    Email: info@qadram.com

    We request that security issues are not publicly disclosed before we have had a reasonable opportunity to investigate and remediate them.

    15. Policy Updates

    We may update this Security Policy as our applications, infrastructure, security practices, or Atlassian requirements change.

    The latest version will always be made available at this location.

    16. Contact

    For security-related questions regarding our Atlassian Marketplace applications, please contact:

    qadram (BranchCreation S.L.U.)

    Website: https://qadram.com

    Email: info@qadram.com