Security & Data Handling
AI Governance Hub is built on Atlassian Forge for Jira Cloud and follows a security-first operating model.
Forge Architecture
The app uses Atlassian Forge and Jira APIs to provide governance workflows inside Jira Cloud. Customers do not need to provide Atlassian passwords, personal access tokens, or shared secrets for normal operation.
Permissions
Governance actions are designed to respect Jira and app-level permission requirements. User-triggered privileged operations should validate authorization before execution.
Public Website Security
The public website pages are static, but the guided assessment flow is server-side: uploads are validated and processed on Vercel serverless infrastructure (United States region by default) solely to generate your report, payments are verified via Razorpay HMAC before release, and downloads use signed expiring tokens. Upload sessions expire within ~24 hours; reports remain recoverable for 90 days unless earlier deletion is requested. No passwords, payment card or UPI data, API keys, or backend credentials are stored in the browser. In-tenant data residency applies to the Atlassian Forge app only — not to website uploads.
Security Contact
Report vulnerabilities or security questions to security@aigovernancehub.ai.
Responsible Disclosure
Please include reproduction steps, impact, affected URL or app area, screenshots where relevant, and your contact information.