Spotlight runs entirely within the Atlassian platform - including its AI. No external servers, no third-party APIs, no write scopes, and no data leaving the Atlassian cloud. Your Jira data stays where it belongs.
Last updated: July 2026
Spotlight has no external backend, no third-party AI provider, and no third-party API calls. Everything - including AI drafting - runs within Atlassian's platform.
Spotlight requests no write permissions at all. It cannot create, modify, or delete issues, projects, boards, or any other Jira data.
Saved spotlights store only their definition - query and settings plus your description. Chart data is fetched live at render time, computed in-memory, and never persisted.
Drafting uses Atlassian-hosted models via Forge LLMs. Prompts never leave the Atlassian platform, issue data is never sent to the model, and prompts are not logged or stored.
How Spotlight accesses, processes, and stores data
Your description plus light site context (project keys and names, status names) goes to an Atlassian-hosted model, which returns a reviewable definition. Issue data is never sent.
Charts and reports fetch live Jira data in the viewing user's browser, with that user's own permissions. Results are computed in-memory and discarded.
Only the definition - settings, query, your description - is written to Forge storage inside your Atlassian tenant. Never the data behind it.
| Data Type | Location | Retention | Encrypted |
|---|---|---|---|
| Spotlight definitions (settings + description) | Forge App Storage (Atlassian cloud) | Until deleted or app uninstalled | ✅ At rest & in transit |
| Sharing permission settings (group names) | Forge App Storage | Until app is uninstalled | ✅ At rest & in transit |
| AI usage counters (monthly call counts) | Forge App Storage | Auto-expire (~3 months) | ✅ At rest & in transit |
| Jira issue data / chart results | - | - | Not stored |
| AI prompt logs | - | - | Not logged |
| Personal user data | - | - | Not collected |
Third-party services involved in data processing
| Service | Provider | Purpose | Data Location | Data Stored |
|---|---|---|---|---|
| Atlassian Forge | Atlassian | App runtime, key-value storage, AI model inference (Forge LLMs) | Per customer's Atlassian data residency | Spotlight definitions, app settings |
Spotlight uses no other sub-processors. There are no external AI providers, no external APIs, and no third-party data processing of any kind.
Every permission explained
Spotlight requests only read scopes plus app storage. No write permissions, no admin permissions, no delete access.
Measures we implement to protect your data
How we handle security incidents and vulnerabilities
Report a security issue: support@bytera.tech - Subject: "Security Incident" or "Vulnerability Report"
Support Portal: Bytera Support
| Phase | Action | Timeline |
|---|---|---|
| Acknowledgment | Confirm receipt and assign severity level | Within 24 hours |
| Triage | Assess scope, impact, and affected systems | Within 48 hours |
| Containment | Isolate affected components; disable features if necessary | Immediate upon confirmation |
| Remediation | Develop and deploy a fix | Based on severity |
| Notification | Notify affected customers with details and remediation steps | Within 72 hours of confirmation |
| Post-Mortem | Document root cause, lessons learned, and preventive measures | Within 2 weeks |
| Severity | Description | Target Resolution |
|---|---|---|
| Critical | Active exploitation, data breach, or complete service compromise | Within 24 hours |
| High | Vulnerability with significant impact potential but no active exploitation | Within 72 hours |
| Medium | Vulnerability with limited impact or requiring specific conditions | Within 1 week |
| Low | Minor issue with minimal security impact | Next scheduled release |
Our severity timelines align with the Atlassian Security Bug Fix Policy for Marketplace Partners.
Regulatory and platform compliance
Bytera follows data minimization and purpose limitation principles. Since Spotlight has no external sub-processors and stores no personal data, the compliance surface is minimal.
Spotlight adheres to all Atlassian Marketplace Partner requirements for security, privacy, and the Security Bug Fix Policy.
By building on Forge, Spotlight inherits Atlassian's SOC 2 Type II certified infrastructure controls and benefits from their security-first platform architecture.
No. Spotlight stores only spotlight definitions - the query, settings, and the description you wrote. Chart data is fetched live at render time, computed in the viewer's browser, and never persisted.
On Atlassian-hosted models via the Forge LLMs platform - inside the Atlassian platform, never a third-party service. It receives your description plus light site context (project keys and names, status names). Issue data is never sent, and prompts are not logged or stored.
No. Spotlight requests no write scopes at all - its Jira access is read-only by construction, and AI-composed report plans are additionally restricted to GET requests on an allowlist of Atlassian REST APIs.
Only the definition: settings, title, the author's description and name. Every viewer renders the spotlight live with their own Jira permissions - sharing can never become a way around Jira access control.
Yes. Since we don't store personal data and have no external sub-processors, the compliance surface is minimal. Users can request data access, correction, or deletion at any time.
All app data (spotlight definitions, settings, usage counters) is removed by the Atlassian Forge platform per Atlassian's standard data-retention policy. No residual data remains.
Please contact us immediately at support@bytera.tech with the subject line "Security Concern". We respond within 24 hours.
We're committed to transparency. If you have any questions about our security practices, data handling, or need additional information for your security review, please don't hesitate to contact us.