TRUST CENTER

Security & trust at Bytera

Transparency builds trust. Here’s exactly how Bytera protects your data, what we run on, and who we work with — across every app we publish on the Atlassian Marketplace.

Built on Atlassian Forge SOC 2 Type II — inherited GDPR Data residency

Security

Our apps run inside Atlassian Forge — a sandboxed, multi-tenant platform — inheriting Atlassian's SOC 2 Type II certified infrastructure controls.

Privacy

Read-only access and data minimization by design. We store only what is strictly required to operate, and never your raw content.

Compliance

GDPR-aligned as a data processor, with Standard Contractual Clauses where any cross-border processing applies.

Reliability

Hosted on Atlassian Cloud’s highly available infrastructure, subject to your organization’s data residency settings.

COMPLIANCE & CERTIFICATIONS

Built on certified foundations

Bytera does not operate separate infrastructure that would require its own SOC 2 or ISO certification. Instead, our apps run entirely within Atlassian Forge and inherit Atlassian’s SOC 2 Type II certified controls — with one exception: XPress uses a stateless cloud rendering service (see Subprocessors). Customer content is processed only within Atlassian and, for XPress exports, in-memory on AWS; Pulse additionally reports usage metrics to an Atlassian-approved analytics tool (no content involved).

Atlassian Forge

All Bytera apps are built entirely on Forge and inherit Atlassian’s SOC 2 Type II certified, security-first cloud infrastructure.

GDPR

Bytera operates as a data processor following data minimization and purpose limitation. SCCs cover any cross-border processing.

Data Residency

App data is stored within Atlassian’s Forge infrastructure, subject to your organization’s Atlassian data residency configuration.

DATA PROTECTION

How we protect your data

Read-only & least privilege

Apps request the minimum scopes needed and read your content only when you initiate an action. They cannot modify, delete, or create content.

Encryption in transit

All data exchanged with Atlassian APIs and any processing service travels over encrypted HTTPS / TLS.

Data minimization

We never persist raw page or issue content. Only aggregated, app-specific data (e.g. scores or settings) is stored within Forge.

Where your data lives

Data stays within your Atlassian Forge environment. XPress’s PDF rendering is processed in-memory in the United States and immediately discarded (zero retention).

SUBPROCESSORS

Who we work with

SubprocessorPurposeAppsLocationData retention
Atlassian Forge platform, storage, app runtime & Forge AI All apps Atlassian Cloud (your residency) Platform-managed
Amazon Web Services (AWS) Stateless PDF rendering XPress only United States (SCCs) Zero — in-memory only
PostHog Usage metrics via an Atlassian-approved analytics tool — feature-usage counts only, no content, no end-user data in scope Pulse only United States Metrics only

SyncUp runs entirely within Atlassian Forge with no external subprocessors. Pulse processes all customer content within Atlassian (including AI features, which use Atlassian Forge AI) — its only outbound connection is usage metrics to an Atlassian-approved analytics tool, declared in the app manifest with end-user data out of scope.

SECURITY PRACTICES

How we operate

Secure development

Forge’s declarative permission model and managed runtime keep our attack surface minimal. Changes ship through Atlassian’s review and distribution pipeline.

Vulnerability management

We monitor dependencies and the Forge platform for advisories and remediate promptly. Responsible disclosure is welcomed (see below).

Incident response

We have a defined process to triage, contain, and communicate security incidents, coordinating with Atlassian where the platform is involved.

Monitoring

Operational health is monitored via AWS CloudWatch for the XPress rendering service. Logs contain metadata only — never customer content.

PER-APP DOCUMENTS

Security & policies by app

Pulse

Content Health for Confluence

XPress

PDF Exporter for Confluence

SyncUp

Sprint Intelligence for Jira

Report a vulnerability

We welcome responsible disclosure. If you believe you’ve found a security issue in any Bytera app, please email us with the details and we’ll respond promptly. Please give us reasonable time to investigate and remediate before any public disclosure.