Security Policy

Last Updated: March 26, 2026

Workflow Flows for Jira

Summary: Workflow Flows for Jira is built with a security-first approach: Forge-hosted execution, least-privilege scopes, user permission checks before app-context reads, secure handling of inputs, and dependency vulnerability scanning.

1. Scope

This policy applies to Workflow Flows for Jira, a Jira Cloud app developed by LND Tech and built on Atlassian Forge.

The app provides issue status-flow timeline insights and project-level admin controls, and does not modify Jira issue data.

2. Authentication & Authorization

3. Least Privilege & Data Handling

Workflow Flows uses only the scopes required for its features:

Data minimization principles applied:

4. Secure Coding Controls

5. Vulnerability Management

References:

6. Incident Response & Communications

If we become aware of a security incident or a critical vulnerability that may affect customers, we will:

7. How to Report a Security Issue

If you discover a security vulnerability in any of our Atlassian apps, please contact us at:

support@lndtech.eu

Please include as much detail as possible (impacted app, steps to reproduce, expected vs. actual behavior, and any relevant logs or screenshots).

Security Contact

Email: support@lndtech.eu

Website: lndtech.eu

LND Tech — Made by Leandro Barreto