1. Security architecture
All of our Apps are built natively on Atlassian Forge and designed to be “Runs on Atlassian” eligible. They run entirely within Atlassian’s cloud infrastructure: we operate no servers, databases, or networks of our own that receive your Atlassian data. This keeps the security exposure surface minimal by design: there is no separate Magrathea-operated backend to attack, and our Apps inherit the security controls and certifications of Atlassian’s platform (for example, SOC 2 and ISO 27001, held by Atlassian as the platform provider).
2. Access control
- Development, deployment, and administrative accounts are protected by multi-factor authentication, including organization-enforced two-factor authentication on our source-control organization.
- Access follows least privilege: our Apps request the minimum Atlassian scopes required, and background operations act as the user who launched them, so an App can only read or change what that user could already do manually.
- All end-user authentication and session management is handled by Atlassian; our Apps maintain no separate login system or user credentials.
3. Data handling
- Encryption. Data at rest is stored exclusively in Atlassian Forge hosted storage, encrypted with AES-256 (keys managed by Atlassian); all in-platform communication uses TLS.
- Data minimization. Our Apps store only the operational metadata required to function and reference users solely by their Atlassian account ID, never names, usernames, or email addresses. Application logs contain operational data only.
- Retention & deletion. Stored data is subject to defined retention limits and is fully deleted when an App is uninstalled.
- Residency. App data is pinned to the host product’s Atlassian data residency location.
4. Secure development & vulnerability management
- Source code is maintained in private version-controlled repositories; releases are typecheck- and test-verified and are reproducible from tagged history for rollback.
- We run dependency scanning (Software Composition Analysis) via automated alerts and dependency review before releases, keeping production dependencies free of known vulnerabilities.
- We monitor and remediate security issues raised through Atlassian’s app security scanning within Atlassian’s required timelines.
- Externally reported vulnerabilities are received and triaged per our disclosure policy.
5. Logging & monitoring
Atlassian Forge provides timestamped platform invocation logs covering all App API activity. Our Apps additionally maintain in-App audit trails of key events, subject to the retention limits above, and we configure error-anomaly alerting on production workloads. Identity, login, session, and multi-factor logging for end users are handled and retained by Atlassian.
6. Incident response
We maintain a documented incident response plan aligned to Atlassian’s Marketplace partner guidance. In the event of a confirmed security incident, we will notify Atlassian promptly (within 24 hours) through Atlassian’s app security incident process, and notify affected customers without undue delay in accordance with our Data Processing Addendum, so that they can meet their own obligations.
7. Governance
These practices are documented in Magrathea’s internal Information Security Policy, approved by company leadership and reviewed at least annually and after any material change or security incident. As our business grows, we expect to expand our controls: for example, longer-term log retention and formal third-party assessments.
8. Contact
Magrathea Software, LLC
Missouri, USA
Security: security@magratheasoftware.com
General: hello@magratheasoftware.com