1. Scope and provider
Craig Technology Services LLC (“CTS,” “we,” “us,” or “our”) provides the four apps named above. This disclosure explains what each app accesses, why it processes that data, what it stores, how deletion works, and the current security boundaries. It supplements the general CTS Website Privacy Policy and does not replace Atlassian’s terms or privacy notices for Jira, Confluence, Marketplace, or Forge.
2. App-specific access, use, and stored data
| App | Data processed to provide the feature | Data retained in Forge app storage |
|---|---|---|
| Link Exposure Guard for Jira read:jira-work storage:app | Explicit links in Jira issue descriptions, plus bounded source identifiers needed to associate findings. | Administrator allowlist and sensitive-query-key settings; one latest report containing run metadata, counts, truncation flags, severity totals, and up to 250 findings with bounded identifiers, hostnames, path shapes, query-key names, and redacted evidence. |
| Link Exposure Guard for Confluence read:page:confluence storage:app | Links in Confluence page content, plus bounded source identifiers needed to associate findings. | Administrator allowlist and sensitive-query-key settings; one latest report containing run metadata, counts, truncation flags, severity totals, and up to 250 findings with bounded identifiers, hostnames, path shapes, query-key names, and redacted evidence. |
| Issue Readiness Guard for Jira read:jira-work storage:app | Issue ID and key, summary and description content, issue type, and assignee account-ID presence needed to apply the configured readiness policy. | The current readiness policy and one latest report containing run metadata, aggregate counts, truncation flags, and up to 250 references with issue ID, issue key, issue type, score, and missing-rule codes. |
| Stale Work Guard for Jira read:jira-work storage:app | Issue ID and key, created and updated timestamps, due date, issue type, status category, and optional assignee account-ID presence. | The current age/due-date policy and one latest report containing run metadata, aggregate counts, truncation flags, and up to 250 references with issue ID, issue key, type, status category, score, band, calculated day counts, and finding codes. |
3. Data deliberately excluded
The Link Exposure Guard apps are designed not to store or log full URLs, URL fragments, embedded credentials, query values, issue summaries, description text, page titles, or page content. Issue Readiness Guard is designed not to store or log summary text, description text, or assignee identity details. Stale Work Guard does not request or store summaries or descriptions and is designed not to store assignee names, email addresses, or account IDs.
None of the four apps sells customer data, creates advertising profiles, uses customer content for model training, fetches external websites represented by scanned links, or changes Jira issues or Confluence pages.
4. Hosting, disclosure, and data location
The apps run on Atlassian Forge and use Forge-hosted app storage. They declare no CTS-operated remote backend, remote endpoint, or external egress. CTS does not independently copy app-processed customer data to a separate vendor database.
Atlassian operates the Forge platform and controls the infrastructure locations used for processing and hosted storage. Forge-hosted data may follow the Atlassian customer’s selected supported location when the product and app are pinned; globally hosted data may be placed or moved among Atlassian-supported realms. Current location behavior and supported regions are described in Atlassian’s Forge data residency documentation (opens in a new tab).
5. Retention and deletion
Each app retains only its current administrator settings and one latest scan report. A completed scan replaces the previous report. Site administrators can delete the latest report from the app’s administrator interface; settings remain until changed. Uninstallation, backup, restoration, and final deletion of Forge-hosted installation data follow Atlassian’s Forge data lifecycle.
For assistance with a privacy or deletion question, email [email protected]. Identify the app and Atlassian site without sending credentials, tokens, full sensitive URLs, or unnecessary customer content.
6. Security controls and boundaries
- Product-specific read scopes and storage:app only;
- no content-write scopes, external egress, or vendor-operated remote backend;
- redaction and minimization before result persistence;
- 5,000-source-record scan cap and 250-stored-finding cap;
- only one latest report retained per installation;
- daily scheduled execution filtered by active licensing;
- production administrative mutations fail closed on explicitly inactive or malformed license context; and
- pagination guards reject missing or repeated continuation tokens.
These are current engineering controls and boundaries, not a penetration-test report, certification, compliance attestation, or guarantee that software is free of vulnerabilities.
7. Vulnerability reporting
Report a suspected vulnerability privately to [email protected]. Include the affected app, observed behavior, reproduction steps, and potential impact. Do not include live credentials, access tokens, or sensitive customer content in the initial message.
8. Changes and contact
Material changes will be reflected by updating the effective date and publishing the revised disclosure at this URL. Questions may be sent to [email protected].
