🛡️Atlassian Forge
🔒Read-Only Access
🏠No External Services
Atlassian-Hosted AI

Spotlight - Security Policy

Spotlight runs entirely within the Atlassian platform - including its AI. No external servers, no third-party APIs, no write scopes, and no data leaving the Atlassian cloud. Your Jira data stays where it belongs.

Last updated: July 2026

🏠

Zero External Services

Spotlight has no external backend, no third-party AI provider, and no third-party API calls. Everything - including AI drafting - runs within Atlassian's platform.

👁️

Read-Only, No Write Scopes

Spotlight requests no write permissions at all. It cannot create, modify, or delete issues, projects, boards, or any other Jira data.

📊

Definitions, Never Data

Saved spotlights store only their definition - query and settings plus your description. Chart data is fetched live at render time, computed in-memory, and never persisted.

AI Inside the Platform

Drafting uses Atlassian-hosted models via Forge LLMs. Prompts never leave the Atlassian platform, issue data is never sent to the model, and prompts are not logged or stored.

Data Handling

How Spotlight accesses, processes, and stores data

Data Flow

1

Draft

Your description plus light site context (project keys and names, status names) goes to an Atlassian-hosted model, which returns a reviewable definition. Issue data is never sent.

2

Render

Charts and reports fetch live Jira data in the viewing user's browser, with that user's own permissions. Results are computed in-memory and discarded.

3

Save

Only the definition - settings, query, your description - is written to Forge storage inside your Atlassian tenant. Never the data behind it.

Data Storage Summary

Data TypeLocationRetentionEncrypted
Spotlight definitions (settings + description)Forge App Storage (Atlassian cloud)Until deleted or app uninstalled✅ At rest & in transit
Sharing permission settings (group names)Forge App StorageUntil app is uninstalled✅ At rest & in transit
AI usage counters (monthly call counts)Forge App StorageAuto-expire (~3 months)✅ At rest & in transit
Jira issue data / chart results--Not stored
AI prompt logs--Not logged
Personal user data--Not collected

Subprocessors

Third-party services involved in data processing

ServiceProviderPurposeData LocationData Stored
Atlassian ForgeAtlassianApp runtime, key-value storage, AI model inference (Forge LLMs)Per customer's Atlassian data residencySpotlight definitions, app settings

Spotlight uses no other sub-processors. There are no external AI providers, no external APIs, and no third-party data processing of any kind.

App Permissions

Every permission explained

read:jira-work
Read issues and run JQL searches; Jira-admin check
read:jira-user
Read group membership for sharing permissions
read:board-scope:jira-software
Identify Scrum boards for velocity charts
read:sprint:jira-software
Read closed sprints for velocity charts
read:issue-details:jira
Access issue fields for chart metrics and groupings
read:jql:jira
Validate JQL with Jira's own parser before saving
read:project:jira
List projects and roles for access reviews
storage:app
Save spotlight definitions and settings in Forge

Spotlight requests only read scopes plus app storage. No write permissions, no admin permissions, no delete access.

Security Controls

Measures we implement to protect your data

🔑 Access Control

  • Viewer-permission rendering: every view uses the viewing user's own Jira permissions
  • Governed sharing: group-based publish/view controls, admin-managed
  • Minimal scopes: read-only APIs plus app storage - nothing else

🧱 Sandboxed Report Plans

  • GET-only: AI-composed plans cannot write anything
  • Endpoint allowlist: Jira, Jira Software, and JSM REST APIs only
  • Hard budgets: capped steps, HTTP calls, and rows per run

🔒 Data Protection

  • No external communication: zero outbound network calls
  • Encryption at rest: Forge storage encrypted by Atlassian
  • No data storage: definitions persisted, never Jira data or prompts

🏗️ Infrastructure

  • Forge sandbox: isolated per-tenant execution
  • No external backend: nothing to attack outside Forge
  • Managed by Atlassian: SOC 2 Type II certified infrastructure

Incident Response

How we handle security incidents and vulnerabilities

Report a security issue: support@bytera.tech - Subject: "Security Incident" or "Vulnerability Report"
Support Portal: Bytera Support

Response Process

PhaseActionTimeline
AcknowledgmentConfirm receipt and assign severity levelWithin 24 hours
TriageAssess scope, impact, and affected systemsWithin 48 hours
ContainmentIsolate affected components; disable features if necessaryImmediate upon confirmation
RemediationDevelop and deploy a fixBased on severity
NotificationNotify affected customers with details and remediation stepsWithin 72 hours of confirmation
Post-MortemDocument root cause, lessons learned, and preventive measuresWithin 2 weeks

Severity Classification

SeverityDescriptionTarget Resolution
CriticalActive exploitation, data breach, or complete service compromiseWithin 24 hours
HighVulnerability with significant impact potential but no active exploitationWithin 72 hours
MediumVulnerability with limited impact or requiring specific conditionsWithin 1 week
LowMinor issue with minimal security impactNext scheduled release

Our severity timelines align with the Atlassian Security Bug Fix Policy for Marketplace Partners.

Compliance

Regulatory and platform compliance

🇪🇺

GDPR

Bytera follows data minimization and purpose limitation principles. Since Spotlight has no external sub-processors and stores no personal data, the compliance surface is minimal.

🏪

Atlassian Marketplace

Spotlight adheres to all Atlassian Marketplace Partner requirements for security, privacy, and the Security Bug Fix Policy.

☁️

Forge Security

By building on Forge, Spotlight inherits Atlassian's SOC 2 Type II certified infrastructure controls and benefits from their security-first platform architecture.

Frequently Asked Questions

Does Spotlight store my Jira data?

No. Spotlight stores only spotlight definitions - the query, settings, and the description you wrote. Chart data is fetched live at render time, computed in the viewer's browser, and never persisted.

Where does the AI run, and what does it see?

On Atlassian-hosted models via the Forge LLMs platform - inside the Atlassian platform, never a third-party service. It receives your description plus light site context (project keys and names, status names). Issue data is never sent, and prompts are not logged or stored.

Can Spotlight modify my Jira data?

No. Spotlight requests no write scopes at all - its Jira access is read-only by construction, and AI-composed report plans are additionally restricted to GET requests on an allowlist of Atlassian REST APIs.

What does sharing a spotlight expose?

Only the definition: settings, title, the author's description and name. Every viewer renders the spotlight live with their own Jira permissions - sharing can never become a way around Jira access control.

Are you GDPR compliant?

Yes. Since we don't store personal data and have no external sub-processors, the compliance surface is minimal. Users can request data access, correction, or deletion at any time.

What happens when I uninstall Spotlight?

All app data (spotlight definitions, settings, usage counters) is removed by the Atlassian Forge platform per Atlassian's standard data-retention policy. No residual data remains.

How do I report a security concern?

Please contact us immediately at support@bytera.tech with the subject line "Security Concern". We respond within 24 hours.

Have a security question?

We're committed to transparency. If you have any questions about our security practices, data handling, or need additional information for your security review, please don't hesitate to contact us.