Перевод для удобства. При расхождении действует английская версия.

Security

ArtUp Trace for Jira Cloud · ArtUp Export for Confluence Cloud · ArtUp Reports for Jira Cloud · ArtUp Query for Jira Cloud · Last updated: 2026-10-05

In short: ArtUp Trace is an Atlassian Forge app with the "Runs on Atlassian" designation. There are no ArtUp Labs servers in the path, no outbound network calls, and no third-party trackers. The App reads Jira as the current user, checks Jira permissions on every action, and never writes to your issues. ArtUp Export reads Confluence as the current user, converts pages in the user's browser, stores nothing and never writes to Confluence. ArtUp Reports reads Jira as the current user, builds Excel, Word and PDF files in the user's browser, stores only export templates and never writes to Jira. ArtUp Query reads Jira work items as the app, keeps an index of ids, dates and metadata in Forge SQL and Forge storage, and never writes to work items.

1. Architecture

ArtUp Trace is built entirely on Atlassian Forge and carries Atlassian's "Runs on Atlassian" designation. This means:

See the Privacy Policy for the full list of what is stored.

1.1 ArtUp Export

ArtUp Export is also built entirely on Atlassian Forge, with no external servers, no Connect modules and only bundled resources.

1.2 ArtUp Reports

ArtUp Reports is also built entirely on Atlassian Forge, with no external servers, no Connect modules and only bundled resources (fonts for Latin, Cyrillic and CJK text, libraries and images).

1.3 ArtUp Query

ArtUp Query is also built entirely on Atlassian Forge, with no external servers, no Connect modules and only bundled resources. It adds JQL functions to Jira (jira:jqlFunction), a reference and status page, and an administration page.

2. Access scopes and permissions

The App follows the principle of least privilege. It requests only the Atlassian scopes it needs, and nothing more:

ArtUp Trace — requested Atlassian scopes
ScopeUsed for
read:jira-workRead issues, issue links and project data needed to compute coverage and detect suspect links.
read:jira-userRead basic information about the current user, used for the per-action Jira permission check.
storage:appStore the App's own settings, requirement/link records and baselines in Forge storage.

ArtUp Trace requests no write scopes for Jira issues. It reads Jira data as the current user, so it can only see what that user is already permitted to see in your Jira site, and it never writes to Jira issues.

Beyond the scopes above, the App performs a Jira permission check on every user-facing action before it acts — for example before showing an issue's traceability data or before recording a link confirmation — so a user cannot use the App to see or affect anything their own Jira permissions would not already allow.

ArtUp Export requests only read scopes. It reads Confluence as the current user, so pages the user cannot see are not exported, and it never writes to Confluence.

ArtUp Export — requested Atlassian scopes
ScopeUsed for
read:page:confluenceRead pages, their content and versions.
read:space:confluenceFind the space and its top-level pages.
read:hierarchical-content:confluenceRead the page tree in Confluence order.
read:attachment:confluenceList and download page attachments.
read:label:confluenceRead page labels for the front-matter.
read:confluence-userRead display names of page authors and mentioned users.
search:confluenceFind pages by title in the page picker.
storage:appDeclared for future versions; not used by the current version, which stores nothing.

ArtUp Reports requests only read scopes and storage:app. It reads Jira as the current user, so issues the user cannot see in Jira are not exported, and it never writes to Jira. Before a user creates, changes or deletes a project or site template, the backend checks that user's Jira permissions (project administration for a project template, Jira administration for a site template); a personal template is visible only to its author.

ArtUp Reports — requested Atlassian scopes
ScopeUsed for
read:jira-workRead issues (search, fields, comments, work logs, links), saved filters, attachments and their thumbnails.
read:jira-userRead display names of authors, assignees and template authors.
read:board-scope:jira-softwareRead the issues of a board or backlog.
read:sprint:jira-softwareRead the issues and details of a sprint.
read:board-scope.admin:jira-softwareRead board configuration, to find the filter behind a board.
read:project:jiraRead the project list for the templates tab and project templates.
storage:appStore export templates in Forge storage.

ArtUp Query reads Jira as the app and requests one write scope, write:app-data:jira, which is used only to store the app's JQL function precomputations. It requests no write:jira-work and no manage:* scope, and it never writes to work items.

ArtUp Query — requested Atlassian scopes
ScopeUsed for
read:jira-workRead work items, links, the hierarchy, the changelog (Sprint, status), comment and attachment metadata, and run JQL searches.
read:jira-userResolve the users that conditions such as by and inRole mean.
read:user:jiraRead group members for inGroup (together with read:group:jira).
read:group:jiraRead groups and their members for inGroup.
read:avatar:jiraComes with the user and group reads; no avatars are stored.
read:board-scope:jira-softwareFind boards for the sprint functions.
read:sprint:jira-softwareRead sprints (ids, names, states).
read:project:jiraRead the project list for the settings page and to check project keys.
read:app-data:jiraRead the state of the app's JQL function precomputations.
write:app-data:jiraStore the app's JQL function precomputations. Not a write to work items.
storage:appThe app's own Forge storage: the update queue, settings and the error log.

3. Application security controls

4. Dependency and supply-chain security

5. Account and workstation security

6. Reporting a vulnerability

If you believe you have found a security vulnerability in ArtUp Trace, ArtUp Export, ArtUp Reports, ArtUp Query or on this website, please email [email protected] with:

Please do not include Jira or Confluence content beyond what is strictly needed to demonstrate the issue, and do not test against customer sites you do not control. We will acknowledge your report within 24 hours and keep you updated as we investigate and fix it. We currently do not run a paid bug bounty programme.

7. Incident response

ArtUp Labs follows a written incident response plan for every Marketplace app, owned by the security contact below and reviewed at least once a year and after every incident.

7.1 What counts as an incident

7.2 Detection channels

7.3 Response steps

Incident response steps and target times
StepTarget timeAction
Acknowledge24 hoursConfirm receipt to the reporter; open an internal incident record (date, source, affected apps, versions).
Triage24 hoursRate severity (Critical / High / Medium / Low); decide whether customer data is affected.
Notify Atlassianwithin 24 hours of becoming aware of an incident affecting customersRaise a P1 ticket with Atlassian Marketplace Security and keep it updated until closed.
Containas soon as possibleRotate compromised credentials (Atlassian API tokens, Forge credentials, source control, DNS, email); revoke sessions; if needed, ship a version that disables the affected feature, or ask Atlassian to pause the app.
Fixwithin the Marketplace Security Bug Fix Policy due dates for the severityPatch, test, deploy to production, and confirm the fix with the reporter or Atlassian.
Notify customerswithin 72 hours of identification, when their data is affectedEmail the technical and billing contacts of affected installations: what happened, what data, what we did, and what they should do.
Closeafter the fix is verifiedWrite a short post-incident review: root cause, timeline, and what changes prevent a repeat.

7.4 Preventive controls

8. Contact

Security contact: [email protected]. For general questions, see our Support page. For what data is stored and how, see our Privacy Policy.