Security policy
Last updated 29 September 2026
How our apps are built
- Every Clearlane app is built on Atlassian Forge and runs on Atlassian’s infrastructure (Runs on Atlassian). We operate no servers of our own.
- Authentication and authorisation are handled by Atlassian. Our apps act with the permissions of the person using them and cannot see anything that person cannot see. One exception: Clearlane Budget reads worklogs with the app’s own access so a budget shows the same figures to everyone allowed to see it; only Jira administrators and the budget managers they name can create budgets, and only for projects they can browse.
- Apps request the smallest set of permissions they need. Clearlane Forecast and Clearlane Pulse only read Jira work; Clearlane Fresh reads Confluence pages and edit dates; Clearlane Gantt changes only dates and “blocks” links; Clearlane Controlled Documents only adds page restrictions, never removes existing ones; Clearlane Answers creates pages and comments only when a person asks or answers, with that person’s permissions; Clearlane Budget only reads Jira work items, worklogs, people and groups.
- No customer content is copied, sent or stored outside Atlassian. The data our apps keep (Clearlane Fresh’s page confirmations, Clearlane Controlled Documents’ document records and audit trail, Clearlane Answers’ topics and question records, Clearlane Budget’s budgets, rates and figures) stays in Atlassian’s storage for your site.
- Signing passwords in Clearlane Controlled Documents are stored only as a salted scrypt hash in Atlassian’s secret storage, and signing locks after repeated failures.
- Logs contain technical counters only (such as the number of work items processed), never customer content.
- We do not ask for passwords, API tokens or other secrets.
Reporting a vulnerability
Write to hello@clearlaneapps.com with the app name, the steps to reproduce and the impact you observed. We acknowledge reports within two business days, keep you informed while we investigate, and fix confirmed issues as a priority. Please give us reasonable time to fix an issue before disclosing it publicly, and do not access or change data that is not yours.