Security
CapacityPulse is designed to minimize data exposure and operational complexity.
Architecture
- Atlassian Forge runtime and Forge-hosted KVS.
- No app-defined external remotes in the current release.
- Read-only Jira access using
api.asUser(). - No external LLM or analytics service.
- No intentional persistence of issue bodies, comments, attachments, or account profiles.
Current Jira scopes
- storage:app
- read:board-scope:jira-software
- read:project:jira
- read:sprint:jira-software
- read:issue-details:jira
Vulnerability reports
Please report security concerns to security@capacitypulse.net. Do not include customer secrets or production credentials in the initial report.