Magrathea Software ← Home

Security

Security Practices

Magrathea Software, LLC · Last updated: July 7, 2026

This page summarizes the information security practices Magrathea Software, LLC (“Magrathea,” “we,” “us”) applies across the applications we distribute through the Atlassian Marketplace (each, an “App”). It is the public companion to our vulnerability disclosure policy.

While Magrathea Software, LLC was formed in 2026, our founder has been building production software since 1997; the company’s oldest live service has run continuously since 2018, and its oldest product since 2019.


1. Security architecture

All of our Apps are built natively on Atlassian Forge and designed to be “Runs on Atlassian” eligible. They run entirely within Atlassian’s cloud infrastructure: we operate no servers, databases, or networks of our own that receive your Atlassian data. This keeps the security exposure surface minimal by design: there is no separate Magrathea-operated backend to attack, and our Apps inherit the security controls and certifications of Atlassian’s platform (for example, SOC 2 and ISO 27001, held by Atlassian as the platform provider).

2. Access control

3. Data handling

4. Secure development & vulnerability management

5. Logging & monitoring

Atlassian Forge provides timestamped platform invocation logs covering all App API activity. Our Apps additionally maintain in-App audit trails of key events, subject to the retention limits above, and we configure error-anomaly alerting on production workloads. Identity, login, session, and multi-factor logging for end users are handled and retained by Atlassian.

6. Incident response

We maintain a documented incident response plan aligned to Atlassian’s Marketplace partner guidance. In the event of a confirmed security incident, we will notify Atlassian promptly (within 24 hours) through Atlassian’s app security incident process, and notify affected customers without undue delay in accordance with our Data Processing Addendum, so that they can meet their own obligations.

7. Governance

These practices are documented in Magrathea’s internal Information Security Policy, approved by company leadership and reviewed at least annually and after any material change or security incident. As our business grows, we expect to expand our controls: for example, longer-term log retention and formal third-party assessments.

8. Contact

Magrathea Software, LLC
Missouri, USA
Security: security@magratheasoftware.com
General: hello@magratheasoftware.com