Security Policy
Perlumetrics Time & Budget – Atlassian Jira Cloud add-on
Last updated: August 2026
1. Reporting security issues
If you discover a security vulnerability in Perlumetrics Time & Budget, please report it to us as soon as possible at security-contact@perlumetrics.com. We take all reports seriously and will acknowledge your message and keep you informed of the resolution.
2. Architecture and hosting
Perlumetrics Time & Budget is built on the Atlassian Forge platform and runs entirely on Atlassian-managed infrastructure. The add-on does not operate its own servers and does not store any data outside of Atlassian Forge (Forge SQL database and Forge Storage).
3. Encryption
- In transit: all communication is encrypted via TLS.
- At rest: data at rest is protected by the encryption managed by the Atlassian Forge platform.
4. Access control
- Access to the add-on is governed by the Jira Cloud permission model and the scopes declared by the app.
- Within the app, fine-grained, group-based authorisation (six personas) ensures each user only sees and changes what they are entitled to.
- The add-on does not store or access user passwords or Atlassian personal access tokens.
5. Data minimisation and logging
The add-on stores only the data required for its functionality and does not log personal data. Administrative actions and status changes on time bookings are recorded in a dedicated audit trail for compliance purposes.
6. Incident management
In the event of a security incident, we will assess the impact, contain it, and notify affected customers without undue delay. Reports can be sent to security-contact@perlumetrics.com.