Security Policy

Issue Autopilot for Jira  ·  Autowork Studios

Effective date: 1 June 2026  ·  Last updated: 1 June 2026

1. Overview

Autowork Studios takes the security of Issue Autopilot and its users' data seriously. This policy describes how we approach security across our app, how we handle vulnerability reports, and how we respond to security incidents.

Issue Autopilot is built exclusively on the Atlassian Forge platform, which provides a sandboxed execution environment with no external servers or databases operated by Autowork Studios. This significantly reduces the attack surface compared to traditionally hosted apps.

2. Platform Security Controls

Because the app runs entirely within Atlassian's Forge infrastructure, the following security controls are inherited from Atlassian's platform:

For full details of Atlassian's infrastructure security controls, refer to Atlassian's Trust & Security page.

3. Application-Level Security Controls

The following controls are implemented within the app itself:

4. Vulnerability Management

We monitor Atlassian's Forge platform release notes and security advisories for any changes that may affect the app. App dependencies are reviewed and updated regularly to address known vulnerabilities.

Because the app has no external infrastructure, the primary vulnerability surface is the app code itself and the Atlassian platform it runs on. Atlassian manages platform-level vulnerabilities; app-level vulnerabilities are addressed by Autowork Studios as described below.

5. Reporting a Security Vulnerability

Responsible disclosure

If you discover a security vulnerability in Issue Autopilot, please report it privately to support@autoworkstudios.com with the subject line "Security vulnerability". Please do not disclose the issue publicly until we have had the opportunity to investigate and remediate it.

When reporting a vulnerability, please include:

We will acknowledge receipt of your report within 2 business days and provide an initial assessment within 5 business days. We are committed to resolving confirmed vulnerabilities promptly and will keep you informed throughout the process.

6. Incident Response

In the event of a confirmed security incident, Autowork Studios will:

Because all data is stored within Atlassian's Forge platform, any infrastructure-level incidents would be handled by Atlassian's security and incident response teams in accordance with their published policies.

7. Access Controls

Issue Autopilot has no backend systems operated by Autowork Studios, so there are no internal access control systems to manage. Access to the app's source code repository is restricted to authorised Autowork Studios personnel only, with access controls enforced via GitHub.

8. Contact

For security-related enquiries, please contact us at:

Autowork Studios
support@autoworkstudios.com