Security
How the apps are built
- Runs on Atlassian. Both apps are Forge apps. Their code runs on Atlassian's infrastructure and their data sits in Atlassian-hosted storage. There are no Pinwheel servers.
- No egress. The apps declare no external network access, so the Forge platform blocks them from sending data outside Atlassian.
- Least privilege. Each app asks only for the Jira scopes its job needs. The scopes are listed on each app's Marketplace page.
- Admins only. The settings pages appear only to Jira admins, and every server-side action checks with Jira that the person calling it is a Jira admin.
- No credentials. The apps never ask for passwords, API tokens, or keys.
- Dependencies are checked with
npm auditbefore each release and kept up to date.
Report a vulnerability
Email support@pinwheelapps.com with "Security" in the subject line. Please include the app, steps to reproduce, and the impact. We follow Atlassian's Marketplace security bug-fix policy for fix timelines, and we will tell affected customers and Atlassian about any security incident.