How we build The mark Documentation Support Contact

Security

Security architecture and disclosure.

Found a vulnerability in anything we have built? Email [email protected] and give us a reasonable window to remediate before public disclosure. We will acknowledge reports within 24 hours, provide regular progress updates, and credit your discovery. Machine-readable security metadata is published per RFC 9116 at /.well-known/security.txt.

Data isolation and zero-egress model

Native Forge execution: no external servers

Our Atlassian apps are built natively on the Atlassian Forge platform. App compute executes in secure serverless microVMs managed directly by Atlassian. All app state is stored through Atlassian's storage:app API and remains housed within your Jira Cloud tenant infrastructure. We operate no external application servers or central databases holding your customer data.

Forge storage

Least-privilege OAuth scopes

Each application requests only the precise OAuth 2.0 scopes necessary to perform its documented function: read-only worklog queries, issue metadata lookups, and private app storage keys. No app requests administrative tenant access or broader account privileges than required.

Least privilege

Zero external data egress

Our apps make no outbound network connections to Layercell infrastructure or third party tracking services. Every API request is confined to your tenant's Jira Cloud REST API under Atlassian's protected network boundary. There are no tracking scripts, remote telemetries, or phone-home beacons.

No egress

Enterprise procurement and vendor assessments

We assist enterprise IT, information security, and procurement teams with vendor security questionnaires, CAIQ-Lite reviews, and architecture verification. Because our apps execute within your existing Atlassian tenant boundary, vendor security risk is contained and transparent. Contact us to initiate a review.

Procurement ready

Vulnerability disclosure policy

Response timelines

We confirm receipt of vulnerability reports within 24 hours. We provide status updates at least every 48 hours until containment or resolution is achieved.

24h response

Safe harbour commitment

We support responsible security research. We will not take legal action against researchers who report security issues in good faith, avoid privacy violations, destruction of data, and service disruption, and allow reasonable time to remediate.

Safe harbour

Public attribution

We credit security researchers publicly on this page and in release notes unless you prefer anonymity.

Attribution

Company details

Registered company

Layercell Ltd is a company registered in England and Wales, company number 17363808. Registered office: 111 Upper Grosvenor Road, Royal Tunbridge Wells, TN1 2EA.

Companies House

Privacy and data rights

Read the privacy notice for details on how personal data is handled under UK GDPR.

Privacy

General support

Customer support and SLA terms are published on the support page.

Support