FlowPaths Legal
Documentation Support

Security Policy — FlowPaths

Effective date: 2026-08-22 · Last updated: 2026-08-22

1. Scope of this document

This page describes how FlowPaths ("the App") is built and operated with respect to security, and how to report a security concern. It complements, and should be read alongside, our Privacy Policy, which covers what data the App accesses and why.

2. Least-privilege access

The App requests the smallest set of Jira permissions ("scopes") it needs to function, and nothing more:

Notably absent: the App does not request read:jira-user, the scope Jira requires to resolve assignee, reporter, or other user-identifying fields. This is a deliberate design choice, not an oversight — the App has no code path that reads, stores, or displays that information, because it was never granted the permission to access it in the first place.

3. Read-only by design

Every Jira API call the App makes is a read (GET/search). The App never creates, edits, or deletes anything in your Jira instance — it has no write scopes at all.

4. No credentials, ever

The App never asks a user for a password, API token, or Personal Access Token (PAT). Authentication and authorization are handled entirely by Atlassian's Forge platform: the App runs under Atlassian's own identity model, and every request is executed either as the viewing user (respecting that user's existing Jira permissions) or as the App's own scoped identity — never with a credential a user has to type in or store.

5. Server-side authorization checks

Configuration reads and writes (status mapping, excluded issues) are scoped to a project using the project key from the request's own trusted Forge context, not a value supplied by the client — so one project's configuration cannot be read or overwritten by a request claiming to be a different project. Board-level data reads are independently cross-checked against that same trusted context before being served, to prevent a request for one board's data being satisfied with another board's configuration.

6. No external network calls

The App makes no calls to any server outside Atlassian's own infrastructure — no analytics, no third-party APIs, no external logging or monitoring service. This is why the App is eligible for Atlassian's "Runs on Atlassian" program, which specifically certifies apps with zero external network egress. There is nothing for the App to leak data to, because it has nowhere else to send it.

7. Dependency management

The App's dependencies are kept current, and known vulnerabilities identified through standard tooling (npm audit) are reviewed and remediated promptly rather than left outstanding.

8. Platform security

The App is built entirely on Atlassian's Forge platform, and inherits Forge's own sandboxing, hosting, and infrastructure security — the App has no servers, databases, or infrastructure of its own to secure or misconfigure.

9. Reporting a security issue

If you believe you've found a security vulnerability in the App, please email info@yourpaths.eu with details. We aim to acknowledge reports promptly and will work with you to understand and address the issue. Please report privately by email rather than in a public issue tracker or forum, to give us a chance to address it before wider disclosure.

10. Changes to this policy

We will update the "Last updated" date above when this policy changes, and post the updated version at the same location.