Security
Security architecture and disclosure.
Found a vulnerability in anything we have built? Email [email protected] and give us a reasonable window to remediate before public disclosure. We will acknowledge reports within 24 hours, provide regular progress updates, and credit your discovery. Machine-readable security metadata is published per RFC 9116 at /.well-known/security.txt.
Data isolation and zero-egress model
Native Forge execution: no external servers
Our Atlassian apps are built natively on the Atlassian Forge platform. App compute
executes in secure serverless microVMs managed directly by Atlassian. All app state
is stored through Atlassian's storage:app API and remains housed within
your Jira Cloud tenant infrastructure. We operate no external application servers or
central databases holding your customer data.
Least-privilege OAuth scopes
Each application requests only the precise OAuth 2.0 scopes necessary to perform its documented function: read-only worklog queries, issue metadata lookups, and private app storage keys. No app requests administrative tenant access or broader account privileges than required.
Zero external data egress
Our apps make no outbound network connections to Layercell infrastructure or third party tracking services. Every API request is confined to your tenant's Jira Cloud REST API under Atlassian's protected network boundary. There are no tracking scripts, remote telemetries, or phone-home beacons.
Enterprise procurement and vendor assessments
We assist enterprise IT, information security, and procurement teams with vendor security questionnaires, CAIQ-Lite reviews, and architecture verification. Because our apps execute within your existing Atlassian tenant boundary, vendor security risk is contained and transparent. Contact us to initiate a review.
Vulnerability disclosure policy
Response timelines
We confirm receipt of vulnerability reports within 24 hours. We provide status updates at least every 48 hours until containment or resolution is achieved.
Safe harbour commitment
We support responsible security research. We will not take legal action against researchers who report security issues in good faith, avoid privacy violations, destruction of data, and service disruption, and allow reasonable time to remediate.
Public attribution
We credit security researchers publicly on this page and in release notes unless you prefer anonymity.
Company details
Registered company
Layercell Ltd is a company registered in England and Wales, company number 17363808. Registered office: 111 Upper Grosvenor Road, Royal Tunbridge Wells, TN1 2EA.
Privacy and data rights
Read the privacy notice for details on how personal data is handled under UK GDPR.
General support
Customer support and SLA terms are published on the support page.