⚡ ATLASSIAN CLOUD FORGE DEVELOPER

Jira & JSM Apps Built on Atlassian Forge.

Inspect current sprint scope and explore tools for sensitive-data handling and Definition of Done workflows. Review each application's availability and documented boundaries.

Forge-hosted compute
Forge-hosted Application Storage
Documented Data Handling
Critical 48-Elapsed-Hour Target

Enterprise Forge Applications

Each product has its own availability and permission boundaries. Sprint Scope Guard is available on Atlassian Marketplace for Jira Cloud. Review sprint changes, agree what moves out, and save a current-sprint report. Start with the first-run guide.

🛡️
● Available on Marketplace

Sprint Scope Guard & Agile JQL Pro

Audit the current active or planned Scrum sprint, with Jira-derived scope data and three custom JQL functions.

  • ✓ Remaining pre-start members form the baseline; removed issues are excluded
  • ✓ Project-scoped JQL: addedToSprintAfterStart("PROJECT_KEY")
  • ✓ Current-sprint scope metrics; no history, forecasts or AI retrospectives
  • ✓ Scope swaps subject to Jira permissions
  • ✓ CSV / JSON / Markdown exports
  • ✓ Free up to 10 users; $1.36/user/month for 11–100, then Marketplace volume rates. Same functions for all teams.
🔒
● Private Pilot

IntraGuard Zero-Egress DLP Firewall

Client-side secret interceptor and PII redaction engine preventing credential leaks in Jira tickets and attachments.

  • ✓ 100+ attack & credential regex detection vectors
  • ✓ High-entropy API key & token discovery
  • ✓ Real-time pre-submit comment & description redaction
  • ✓ Merkle SHA-256 tamper-proof incident ledger
  • ✓ Zero-Egress execution: no token ever leaves Jira
✅
● Public Beta

Smart Defaults & DoD Enforcer

Automated Definition of Done gates, workflow transition validators, and intelligent checklist enforcement.

  • ✓ Blocks "Done" transition until mandatory criteria pass
  • ✓ Contextual checklist templates by issue type
  • ✓ Strict role-based sign-off authorization
  • ✓ Automated sub-task & dependency verification
  • ✓ Responsive Forge UI Kit integration with caching where applicable
📬
● In Development

JSM Outgoing Email & Delivery Audit Trail

Tamper-proof delivery verification and compliance receipts for Jira Service Management customer communications.

  • ✓ Complete outgoing notification timeline per ticket
  • ✓ SMTP response status, bounce & drop diagnostics
  • ✓ Global compliance search with date & recipient filters
  • ✓ 90-day encrypted audit retention in Forge KVS
  • • Planned audit bundle export for evidence preparation

Documented Data Boundaries

Review the Complete Data Flow

The current major-4 release of Sprint Scope Guard runs on Forge and stores settings plus minimal governance data in Forge KVS. Removed-item audit entries contain only the issue key, action reason, and action date; current Jira fields are fetched as the current user reads them, inaccessible or deleted issues are omitted, and Jira remains the source of truth. Browser exports create a local copy for the user.

It has no external backend destination or telemetry. Browser exports remain local to the user. Forge operational logs, metrics, and alerts are Atlassian-managed platform services and may include platform site, version, and invocation metadata, governed by the customer's log-sharing settings. Consult the security policy for version-specific details.

Read Complete Security Policy →
DATA FLOW AUDIT SPECIFICATION
[Customer Jira Cloud Instance]
  │
  ▼ (Atlassian Internal Forge Runtime)
  ├── Sprint Scope Guard Core [Forge]
  ├── IntraGuard DLP Interceptor [Zero-Egress]
  └── Forge KVS [Atlassian-managed]
  → Forge-native operations: PLATFORM-MANAGED
  → logs / metrics / alerts; customer log-sharing controls
  → Forge logs: PLATFORM METADATA
  ✓ No external telemetry vendor in the remediation
48h target
Critical Vulnerability SLA
Critical vulnerabilities target 48 elapsed hours after validation; High vulnerabilities target 7 business days. These are targets, not guarantees.
24h target
Security Incident Notice
Security incident notification targets 24 elapsed hours after confirmation, subject to incident validation and available contact details.
Forge
Operational Diagnostics
The Sprint Scope Guard remediation uses minimal application messages. Forge adds platform metadata; logs are not anonymous. No external telemetry vendor is introduced.
Review
Privacy & Contracts
Forge hosting does not establish the operator's legal role or an app certification. Review documented data handling and applicable contracts before deployment.