Linkwright

Security Policy — Linkwright for Jira

Effective date: 30 September 2026

Architecture

Linkwright for Jira runs entirely on Atlassian Forge. Its code executes on Atlassian’s infrastructure and its data lives in the Forge storage of each customer’s Jira site, isolated from every other customer. We operate no server, database or log pipeline of our own.

Authentication of incoming data

The only inbound endpoint is the web trigger that receives GitHub webhooks. Every delivery must carry a valid HMAC-SHA256 signature computed with a secret unique to the customer’s site; the signature is checked in constant time on the raw request body. Unsigned, mis-signed or malformed deliveries are rejected. Replayed deliveries are detected and ignored.

Least privilege

Secrets

The GitHub App private key is held in Forge encrypted environment variables. Installation tokens and per-site webhook secrets are held in Forge encrypted storage. The GitHub OAuth token of the administrator who associates an organization is held and refreshed by Forge. No secret is written to logs, URLs or source code.

Data handling

Logs contain identifiers, repository and branch names, issue keys, counters and error messages; never commit messages, author names, emails, tokens or secrets. Database queries are parameterized. See the Privacy Policy for the full list of data processed and retention.

Dependencies

Production dependencies are audited before every release; no release ships with a known critical or high vulnerability.

Reporting a vulnerability

Email security@linkwright.io. We acknowledge reports within 2 business days and fix vulnerabilities within the timeframes of the Atlassian Marketplace Security Bug Fix Policy (critical: 10 days). Please do not disclose publicly before a fix is released.