Security Policy — Linkwright for Jira
Effective date: 30 September 2026
Architecture
Linkwright for Jira runs entirely on Atlassian Forge. Its code executes on Atlassian’s infrastructure and its data lives in the Forge storage of each customer’s Jira site, isolated from every other customer. We operate no server, database or log pipeline of our own.
Authentication of incoming data
The only inbound endpoint is the web trigger that receives GitHub webhooks. Every delivery must carry a valid HMAC-SHA256 signature computed with a secret unique to the customer’s site; the signature is checked in constant time on the raw request body. Unsigned, mis-signed or malformed deliveries are rejected. Replayed deliveries are detected and ignored.
Least privilege
- On GitHub, the app reads only the repositories the GitHub account owner granted it, and manages only the webhooks it created itself. It never writes code, pull requests or other webhooks. It reads organization membership only to check that the administrator who connects an installation to Jira controls it.
- A repository only feeds issues of the Jira projects it is attached to.
- Associating a GitHub organization with a Jira site requires a Jira administrator who is also an owner of that GitHub organization, checked on GitHub at association time.
- Each Jira permission scope requested is used by the code and justified in the listing.
Secrets
The GitHub App private key is held in Forge encrypted environment variables. Installation tokens and per-site webhook secrets are held in Forge encrypted storage. The GitHub OAuth token of the administrator who associates an organization is held and refreshed by Forge. No secret is written to logs, URLs or source code.
Data handling
Logs contain identifiers, repository and branch names, issue keys, counters and error messages; never commit messages, author names, emails, tokens or secrets. Database queries are parameterized. See the Privacy Policy for the full list of data processed and retention.
Dependencies
Production dependencies are audited before every release; no release ships with a known critical or high vulnerability.
Reporting a vulnerability
Email security@linkwright.io. We acknowledge reports within 2 business days and fix vulnerabilities
within the timeframes of the Atlassian Marketplace Security Bug Fix Policy (critical: 10 days).
Please do not disclose publicly before a fix is released.