Trust Center

Security & Compliance

Armada is built on Atlassian Forge. Its data is stored in Atlassian's Forge storage for your site, and it runs no external servers.

100%Forge-Native
0External Servers
180dAudit log retention
RoARuns on Atlassian

How Armada handles your data

Built on Atlassian Forge

Armada runs on Atlassian Forge and stores its data in Atlassian's Forge storage for your site. It runs no servers of its own.

  • Runs in the Forge sandboxed runtime
  • No external servers or databases
  • Runs on Atlassian badge on the Marketplace listing
  • No data sent to third-party services

Data Protection

Encryption and isolation are provided by Atlassian's Forge platform.

  • Forge storage is encrypted at rest by Atlassian
  • TLS encryption in transit
  • Data scoped to your Jira site installation
  • No credentials or API tokens stored

Compliance, stated plainly

Armada holds no certifications of its own. It runs on Atlassian's infrastructure, which Atlassian's own compliance program covers.

  • No independent SOC 2 or ISO 27001 report for Armada
  • Atlassian's certifications: see Atlassian Trust Center
  • Data processing described in our Privacy Policy
  • Audit log retained 180 days

Transparency

What we access, why, and how long we keep it.

  • Scopes listed with their purpose below
  • Retention windows published
  • Audit trail for governance actions
  • Open vulnerability disclosure

Compliance

Armada does not hold its own SOC 2 or ISO 27001 certification. It runs on Atlassian's Forge platform; for the certifications that cover Atlassian's infrastructure, see theAtlassian Trust Center.

Runs on Atlassian

Shown on the Armada Marketplace listing. No external servers.

Atlassian platform

Forge infrastructure is covered by Atlassian's compliance program, not by a separate Armada certification.

GDPR

Data processed, retention and your rights are set out in the Privacy Policy.

Retention

Audit log 180 days. Outcome events 90 days.

Permission Transparency

Armada follows the principle of least privilege. Here's exactly what we request and why.

read:jira-work

Read issue and project data to show campaign status and check fleet health

write:jira-work

Create team issues, add nudge comments, and create or remove issue links

read:jira-user

Search users for assignee autocomplete and resolve display names

storage:app

Store campaign state, fleet configuration and the audit log in Forge storage

read/write:component:compass

Show campaign progress on Atlassian Compass component pages

read/write:event:compass, read/write:metric:compass

Publish campaign events and progress metrics to Compass components

Data Flow Architecture

Your Users
Jira Cloud
Armada on Forge

Armada's data is stored in Atlassian's Forge storage. Armada runs no external servers and calls no third-party APIs.

System Status

Checking status...

Armada runs on Atlassian Forge infrastructure. For platform status, visit theAtlassian Status Page

Security Contact

Vulnerability Disclosure

Found a security issue? Report it responsibly.

security@armada.run

Security Questions

Questions about our security practices?

security@armada.run

Compliance Inquiries

Need compliance documentation?

compliance@armada.run