This Security Policy describes how Alpha Tecnologia ("we") protects customer data and handles security for the Alpha Checklist application, distributed for Jira and Jira Service Management through the Atlassian Forge platform.
Alpha Checklist runs entirely on Atlassian Forge. It does not use external servers or third-party infrastructure: all data is stored within the Atlassian cloud environment using Forge Hosted Storage and Jira issue properties. This means our security posture is built on, and inherits, the controls of the Atlassian platform.
1. Reporting a Security Issue
If you discover a security vulnerability or have a security concern about Alpha Checklist, please contact us as soon as possible at:
Please include a description of the issue, the steps to reproduce it, and any relevant details (affected version, environment, screenshots). We ask that you report issues privately and give us a reasonable opportunity to remediate before any public disclosure.
2. How We Handle Security Incidents
When a security issue or incident is reported or detected, we follow these steps:
- Acknowledgement — We acknowledge valid security reports within 3 business days.
- Assessment — We investigate and classify the severity and impact of the issue.
- Containment & remediation — We work to contain and fix confirmed issues as a priority, with critical vulnerabilities addressed as quickly as possible.
- Notification — In the event of a security incident affecting customer data, we will notify the affected customers and Atlassian in accordance with Atlassian Marketplace security incident guidelines.
- Post-incident review — After resolution, we review the root cause and apply preventive measures.
3. Vulnerability Management
We manage vulnerabilities through an ongoing process of reporting, triage and remediation:
- Reporting — Vulnerabilities can be reported by customers, researchers or identified internally, and through the Atlassian Marketplace Security Bug Bounty program, in which the app participates.
- Triage — Each report is reviewed, validated and prioritized based on severity and potential impact.
- Remediation — Confirmed vulnerabilities are fixed and deployed following Atlassian's Marketplace Security Bug Fix Policy timelines for their severity level.
- Dependencies — We perform dependency/software composition analysis (e.g., npm audit) to keep third-party libraries free of known vulnerabilities, and we monitor and update dependencies as needed.
4. Key Security Controls
The following security controls are in place for Alpha Checklist:
- Access control — Authentication and authorization are handled by the Atlassian platform. The app respects Jira project permissions and provides its own role-based administration (global and project administrators). The app does not request, store or share Atlassian Personal Access Tokens (PATs), user passwords or other shared secrets.
- Data protection — All data is stored within the Atlassian cloud using Forge Hosted Storage and Jira issue properties, with encryption in transit and at rest provided by the Atlassian platform. No customer data leaves the Atlassian infrastructure.
- Least privilege — The app requests only the minimum Forge scopes required to operate, and processes only the operational data needed to deliver its features.
- Monitoring & logging — The app maintains an internal audit log of administrative and checklist actions, and relies on Forge platform logging for operational monitoring and diagnostics.
- Secure development — Security is considered during development through code review, dependency scanning and awareness of the OWASP Top 10 risks.
- Account security — Source code and developer accounts are protected with multi-factor authentication (MFA) and strong password practices.
5. Data Privacy
For details on how data is collected, processed, stored and deleted, please see our Privacy Policy.
6. Contact
For any security-related questions or to report a vulnerability, contact us at checklist@alphatecapp.com.