Safety Net for Jira Coming soon — get notified

Security

Last updated 4 October 2026

Safety Net is installed into the system that holds your team’s work, so it is designed to need as little trust as possible.

Runs on Atlassian

  • ✓ Compute and storage are provided by Atlassian’s Forge platform. We operate no servers or databases.
  • ✓ No external connections: the app can’t send your data outside Atlassian.
  • ✓ Stored data follows your site’s data residency region and is deleted by Atlassian when the app is uninstalled.
  • ✓ Encryption in transit and at rest is provided by the platform.

Access

  • ✓ Least-privilege scopes: read and write work items, read users (account ids, for names), and app storage. No Jira configuration access.
  • ✓ Every action checks the person’s own Jira permissions first; admin features require Jira or project administrator rights.
  • ✓ Single-value restores on a work item run as the person, so Jira enforces their edit rights.
  • ✓ Every undo, restore and settings change is recorded in an audit log for your administrators.

Data minimisation

  • ✓ Only Atlassian account ids are stored — no email addresses.
  • ✓ Deleted files are not copied.
  • ✓ Retention is yours to choose (7–365 days); expired data is erased automatically.
  • ✓ Closed Atlassian accounts are erased through Atlassian’s personal data reporting.

Engineering

  • ✓ Strict input validation and a generic error policy on every API endpoint.
  • ✓ Automated tests for permission checks, input validation and every undo and restore path.
  • ✓ Dependency audits, secret scanning and static analysis on every change; pinned build actions.

Report a vulnerability

Email enquiry@synexcodigital.com with “Security” in the subject. We acknowledge reports within 2 business days and fix critical issues as a priority, following Atlassian’s Marketplace security requirements. Please don’t access other customers’ data or degrade the service while testing. See also security.txt.