Queue Coverage security and support
The app uses Atlassian Forge. The privacy-reporting candidate uses read:jira-work, read:servicedesk-request, storage:app and report:personal-data. There are no Jira write permissions or external runtime destinations.
Implemented controls
- Current-user Jira reads with fixed, validated routes; no asApp fallback or customer-supplied tokens.
- Server-derived identity and installation context; paid user functions require an active Marketplace license. Privacy lifecycle maintenance does not require paid entitlement and reads no Jira source data.
- Project administrator checks for policy/exclusion changes and fresh issue authorization for each exclusion.
- Repeated universe and queue reads before releasing rows or CSV; incomplete or changed data blocks definitive conclusions.
- Conditional immutable policy writes reject concurrent overwrites. Private run metadata is separated by current account/project.
- CSV formula neutralization and UI text rendering; no interpretation of Jira text as instructions.
Retention
See the Privacy Notice. History expires after 30 days; configuration revisions do not. Exclusion expiry changes eligibility and does not erase historical revisions. Uninstallation follows Atlassian's retention lifecycle, not immediate physical erasure.
Validation status
Release validation is in progress. Local tests and bounded development checks are not an independent penetration test or security certification. No certification or guarantee that all attacks have been excluded is claimed.
Support
Contact support@profitsignallabs.dev or the support portal. Approved response commitments are 24 hours for requests Atlassian designates critical and five business days for other requests; these are response targets, not guaranteed resolution times.
Report the action, approximate time and sanitized error text first. Do not include tokens, full Jira exports or sensitive records. A suitable minimal-data channel will be agreed if further information is needed.