Security Policy — FlowPaths
1. Scope of this document
This page describes how FlowPaths ("the App") is built and operated with respect to security, and how to report a security concern. It complements, and should be read alongside, our Privacy Policy, which covers what data the App accesses and why.
2. Least-privilege access
The App requests the smallest set of Jira permissions ("scopes") it needs to function, and nothing more:
read:jira-work,read:project:jira,read:board-scope:jira-software,read:board-scope.admin:jira-software,read:filter:jira— all read-only, used to read issues, board configuration, and saved filters.storage:app— used only to save the small per-project configuration described in our Privacy Policy §6 (status mapping, excluded issues).
Notably absent: the App does not request read:jira-user,
the scope Jira requires to resolve assignee, reporter, or other user-identifying
fields. This is a deliberate design choice, not an oversight — the App has no code
path that reads, stores, or displays that information, because it was never granted
the permission to access it in the first place.
3. Read-only by design
Every Jira API call the App makes is a read (GET/search). The App never creates, edits, or deletes anything in your Jira instance — it has no write scopes at all.
4. No credentials, ever
The App never asks a user for a password, API token, or Personal Access Token (PAT). Authentication and authorization are handled entirely by Atlassian's Forge platform: the App runs under Atlassian's own identity model, and every request is executed either as the viewing user (respecting that user's existing Jira permissions) or as the App's own scoped identity — never with a credential a user has to type in or store.
5. Server-side authorization checks
Configuration reads and writes (status mapping, excluded issues) are scoped to a project using the project key from the request's own trusted Forge context, not a value supplied by the client — so one project's configuration cannot be read or overwritten by a request claiming to be a different project. Board-level data reads are independently cross-checked against that same trusted context before being served, to prevent a request for one board's data being satisfied with another board's configuration.
6. No external network calls
The App makes no calls to any server outside Atlassian's own infrastructure — no analytics, no third-party APIs, no external logging or monitoring service. This is why the App is eligible for Atlassian's "Runs on Atlassian" program, which specifically certifies apps with zero external network egress. There is nothing for the App to leak data to, because it has nowhere else to send it.
7. Dependency management
The App's dependencies are kept current, and known vulnerabilities identified
through standard tooling (npm audit) are reviewed and remediated
promptly rather than left outstanding.
8. Platform security
The App is built entirely on Atlassian's Forge platform, and inherits Forge's own sandboxing, hosting, and infrastructure security — the App has no servers, databases, or infrastructure of its own to secure or misconfigure.
9. Reporting a security issue
If you believe you've found a security vulnerability in the App, please email info@yourpaths.eu with details. We aim to acknowledge reports promptly and will work with you to understand and address the issue. Please report privately by email rather than in a public issue tracker or forum, to give us a chance to address it before wider disclosure.
10. Changes to this policy
We will update the "Last updated" date above when this policy changes, and post the updated version at the same location.