🛡️Atlassian Forge
🔒Read-Only Access
🏠No External Services
🇪🇺GDPR Compliant

SyncUp — Security Policy

SyncUp runs entirely within the Atlassian Forge platform. No external servers, no third-party APIs, no data leaving the Atlassian cloud. Your sprint data stays where it belongs.

Last updated: May 2026

🏠

Zero External Services

Unlike many Marketplace apps, SyncUp has no external backend, no cloud rendering service, and no third-party API calls. Everything runs within Atlassian's Forge sandbox.

👁️

Read-Only Access

SyncUp only reads your Jira data — it cannot modify, delete, or create any issues, sprints, or boards. The minimum possible permission footprint.

📊

No Raw Content Storage

SyncUp never stores your issue descriptions or comments. Only aggregated sprint metrics are persisted. Your data is analyzed in-memory and immediately discarded.

🔐

Zero Personal Data

We do not collect, store, or process any personal user data. No analytics, no tracking, no advertising — ever.

Data Handling

How SyncUp accesses, processes, and stores data

Data Flow

1

Sprint Analysis

SyncUp reads your Jira sprints and issues through official Atlassian APIs within the Forge sandbox. Data is analyzed in-memory using our proprietary analysis engine.

2

Metric Aggregation

Only aggregated, numerical metrics are stored in Forge SQL. No raw issue content, no user data, no content copies.

3

Dashboard Display

Metrics are displayed in the app's project page. All data remains within the Atlassian cloud environment at all times.

Data Storage Summary

Data TypeLocationRetentionEncrypted
Aggregated sprint metricsForge SQL (Atlassian cloud)Until app is uninstalled✅ At rest & in transit
Velocity historyForge SQL (Atlassian cloud)Until app is uninstalled✅ At rest & in transit
App configurationForge App StorageUntil app uninstalled✅ At rest & in transit
Raw issue contentNot stored
Personal user dataNot collected

Subprocessors

Third-party services involved in data processing

ServiceProviderPurposeData LocationData Stored
Atlassian Forge Atlassian App runtime, SQL database, storage Per customer's Atlassian data residency Aggregated metrics, app config

SyncUp uses no other sub-processors. There are no external APIs, no cloud rendering services, and no third-party data processing of any kind.

App Permissions

Every permission explained

read:jira-work
Read issues, statuses, and assignments
read:sprint:jira-software
Access sprint data for analysis
read:board-scope:jira-software
Identify active boards and sprints
read:issue-details:jira
Access issue metadata for brief generation
read:project:jira
List projects for report organization
read:user:jira
Identify user for role-based briefs

SyncUp requests only read scopes. No write permissions, no admin permissions, no delete access.

Security Controls

Measures we implement to protect your data

🔑 Access Control

  • Read-only access: SyncUp cannot modify any Jira data
  • Jira permissions: Respects native permission model
  • Minimal scopes: Only read API scopes — the minimum necessary

🔒 Data Protection

  • No external communication: Zero outbound network calls
  • Encryption at rest: Forge SQL encrypted by Atlassian
  • No raw content storage: Only numerical metrics persisted

🏗️ Infrastructure

  • Forge sandbox: Isolated per-tenant execution
  • No external backend: Nothing to attack outside Forge
  • Managed by Atlassian: SOC 2 Type II certified infrastructure

📊 Development

  • Dependency scanning: Regular audits for known CVEs
  • Code review: Security-focused assessment
  • Minimal dependencies: Reduced attack surface

Incident Response

How we handle security incidents and vulnerabilities

Report a security issue: support@bytera.tech — Subject: "Security Incident" or "Vulnerability Report"
Support Portal: Bytera Support

Response Process

PhaseActionTimeline
AcknowledgmentConfirm receipt and assign severity levelWithin 24 hours
TriageAssess scope, impact, and affected systemsWithin 48 hours
ContainmentIsolate affected components; disable features if necessaryImmediate upon confirmation
RemediationDevelop and deploy a fixBased on severity
NotificationNotify affected customers with details and remediation stepsWithin 72 hours of confirmation
Post-MortemDocument root cause, lessons learned, and preventive measuresWithin 2 weeks

Severity Classification

SeverityDescriptionTarget Resolution
CriticalActive exploitation, data breach, or complete service compromiseWithin 24 hours
HighVulnerability with significant impact potential but no active exploitationWithin 72 hours
MediumVulnerability with limited impact or requiring specific conditionsWithin 1 week
LowMinor issue with minimal security impactNext scheduled release

Our severity timelines align with the Atlassian Security Bug Fix Policy for Marketplace Partners.

Compliance

Regulatory and platform compliance

🇪🇺

GDPR

Bytera follows data minimization and purpose limitation principles. Since SyncUp has no external sub-processors and stores no personal data, the compliance surface is minimal.

🏪

Atlassian Marketplace

SyncUp adheres to all Atlassian Marketplace Partner requirements for security, privacy, and the Security Bug Fix Policy.

☁️

Forge Security

By building on Forge, SyncUp inherits Atlassian's SOC 2 Type II certified infrastructure controls and benefits from their security-first platform architecture.

Frequently Asked Questions

Does SyncUp store my Jira issue content?

No. SyncUp analyzes sprint and issue data in-memory and only stores aggregated numerical metrics. Your issue descriptions, comments, and attachments are never copied, stored, or persisted.

Does any data leave the Atlassian cloud?

No. SyncUp runs entirely within the Atlassian Forge platform. There are no external API calls, no external backends, and no data transmission outside of Atlassian's infrastructure.

Can SyncUp modify my Jira issues?

No. SyncUp has strictly read-only access. It cannot create, modify, or delete any issues, sprints, or project configurations in your Jira instance.

Are you GDPR compliant?

Yes. Since we don't store personal data and have no external sub-processors, the compliance surface is minimal. Users can request data access, correction, or deletion at any time.

What happens when I uninstall SyncUp?

All app-related data (sprint snapshots, velocity history, configuration) is automatically removed by the Atlassian Forge platform. No residual data remains.

How do I report a security concern?

Please contact us immediately at support@bytera.tech with the subject line "Security Concern". We respond within 24 hours.

Have a security question?

We're committed to transparency. If you have any questions about our security practices, data handling, or need additional information for your security review, please don't hesitate to contact us.