Security & Data Handling

AI Governance Hub is built on Atlassian Forge for Jira Cloud and follows a security-first operating model.

Forge Architecture

The app uses Atlassian Forge and Jira APIs to provide governance workflows inside Jira Cloud. Customers do not need to provide Atlassian passwords, personal access tokens, or shared secrets for normal operation.

Permissions

Governance actions are designed to respect Jira and app-level permission requirements. User-triggered privileged operations should validate authorization before execution.

Public Website Security

The public website pages are static, but the guided assessment flow is server-side: uploads are validated and processed on Vercel serverless infrastructure (United States region by default) solely to generate your report, payments are verified via Razorpay HMAC before release, and downloads use signed expiring tokens. Upload sessions expire within ~24 hours; reports remain recoverable for 90 days unless earlier deletion is requested. No passwords, payment card or UPI data, API keys, or backend credentials are stored in the browser. In-tenant data residency applies to the Atlassian Forge app only — not to website uploads.

Security Contact

Report vulnerabilities or security questions to .

Responsible Disclosure

Please include reproduction steps, impact, affected URL or app area, screenshots where relevant, and your contact information.