Keystone Apps
Keystone Apps

Security

We follow Atlassian Forge best practices and least-privilege scopes.

Platform

  • Apps are built on Atlassian Forge and use Atlassian-managed infrastructure.
  • App operational data is stored using Atlassian Forge platform storage, including Forge KVS where applicable.
  • Scoped OAuth permissions are used so apps request only the permissions needed for their functionality.

Operational

  • Continuous updates, minimal data retention, and logging of errors only.
  • Security updates prioritized as critical fixes.