TRUST · SECURITY

Security Statement

Last updated · October 2026

Overview

Armada is built on Atlassian Forge, Atlassian's secure, cloud-native app development platform. This architecture ensures your data remains within Atlassian's trusted infrastructure at all times.

Forge-Native Architecture

As a Forge app, Armada benefits from:

  • Sandboxed Execution: All code runs in Atlassian's isolated runtime environment
  • No External Servers: No data is transmitted to or stored on third-party infrastructure
  • Platform Patching: Atlassian maintains and patches the Forge runtime
  • Runs on Atlassian: The Armada Marketplace listing carries the Runs on Atlassian badge

Data Security

Data at Rest

All configuration and campaign data is stored in Forge storage, which Atlassian encrypts at rest.

Data in Transit

All communications between Armada and Jira APIs occur within Atlassian's internal network using TLS 1.2+ encryption.

Data Isolation

Each Jira site's data is logically isolated. Armada cannot access data from other Atlassian sites or tenants.

Authentication & Authorization

  • No Credentials Stored: Armada does not store user passwords or API tokens
  • Permission Inheritance: Users can only access issues they have permission to view in Jira
  • Scoped Access: Armada requests only the minimum permissions required:
    • read:jira-work - Read issue and project data
    • write:jira-work - Create issues and add comments
    • read:jira-user - User search and display name resolution
    • storage:app - Store configuration data
    • read:component:compass, write:component:compass, and the matching event and metric scopes - Show campaign progress in Atlassian Compass

User Data Usage

Armada uses the Jira Cloud REST API (/rest/api/3/user/search and /rest/api/3/user) with the read:jira-user scope to:

  • Provide assignee autocomplete in the Armada UI
  • Resolve Jira accountIds to display names for better readability

This data is processed transiently inside the Atlassian Forge runtime. Armada does not persist user profile data (name, email, etc.) in any external storage and does not send it to any third-party service. Only Atlassian accountId references may be stored for technical purposes (e.g., tracking who launched a campaign).

Secure Development Practices

  • Input Validation: All user inputs are validated using Zod schemas
  • Rate Limiting: API calls are rate-limited to prevent abuse
  • Error Handling: Errors are sanitized to prevent information leakage
  • Dependency Scanning: Automated vulnerability scanning for all dependencies
  • Code Review: All changes undergo peer review before deployment

Audit Trail

Armada maintains audit logs for governance-related actions including:

  • Campaign launches and recalls
  • Approval requests and decisions
  • Configuration changes

Logs are stored in Forge Storage and accessible to Jira administrators.

Incident Response

In the event of a security incident:

  • We follow Atlassian's incident response procedures
  • Affected customers will be notified within 72 hours
  • Post-incident reports are available upon request

Compliance

Armada does not hold its own SOC 2 or ISO 27001 certification. It runs on Atlassian's Forge platform, and Atlassian's certifications cover Atlassian's infrastructure, not Armada as a vendor. See theAtlassian Trust Centerfor those reports.

  • GDPR: Data processed, retention and your rights are described in the Privacy Policy
  • Storage: Data is stored in Atlassian's Forge storage for your Jira site
  • Retention: Audit log 180 days; outcome events 90 days

Vulnerability Disclosure

If you discover a security vulnerability, please report it responsibly:

  • Email: security@armada.run
  • Include detailed reproduction steps
  • Allow reasonable time for remediation before public disclosure

Contact

For security-related questions or concerns, contact us at security@armada.run.