Legal
Security Statement
How we protect your data — and what we rely on others to protect.
Last updated: July 2, 2026
Our approach
We believe in transparency. This page clearly separates what we build and control from what the Atlassian Forge platform provides. We don't claim certifications we don't hold.
1. Architecture
SuperTemplates is built on Atlassian Forge, Atlassian's cloud app platform. This means:
- No external servers — the App runs entirely on Atlassian's infrastructure
- No external databases — all persistent data is stored in Forge Key-Value Storage
- No self-hosted backend — there is no server we operate that stores or processes your Jira data
AI inference runs on Atlassian's Forge-hosted LLM, inside Atlassian's infrastructure — AI prompts never leave the Atlassian platform. The only declared outbound network call from the App is to our analytics provider (PostHog, EU), which site administrators can disable. With analytics disabled, no data is sent outside Atlassian infrastructure.
SuperTemplates is operated by a registered business (działalność gospodarcza) in Poland.
2. What We Build and Control
Security measures implemented by SuperTemplates directly.
Smart Anonymization
Before data is sent to the AI model (Atlassian's Forge-hosted LLM), we automatically pseudonymize known Jira user identifiers — display names from your project's member list are replaced with anonymous codes (e.g., “U1”), and system identifiers such as Atlassian account IDs, email addresses, project keys, and board names are stripped. The model never sees these identifiers. Important: Free-text content you enter in prompts is sent to the model as written. You are responsible for not including sensitive personal data in AI generation prompts.
Minimal Data Access
The App requests only the Jira scopes necessary for its functionality. We never read existing issue content (titles, descriptions, comments, attachments). We access project metadata (issue types, priorities, fields, sprints) only to populate the editor UI.
No API Keys
AI inference is provided by Atlassian's Forge-hosted LLM, authenticated by the Forge platform itself. The App holds no AI provider credentials, so there are no keys to leak, rotate, or manage.
Admin Controls
Site administrators can view per-user usage statistics and disable analytics egress entirely. The App functions normally without analytics.
Code Practices
All code is reviewed before deployment. The App is built on Atlassian Forge, which enforces sandboxed execution and declared egress. Dependencies are regularly audited for known vulnerabilities.
3. What Atlassian Forge Provides
Security measures provided by the Forge platform. We rely on these but do not operate them ourselves.
| Measure | Detail |
|---|---|
| Encryption at rest | AES-256 via AWS infrastructure |
| Encryption in transit | TLS 1.2+ |
| Data residency | Forge storage respects your Atlassian data residency region |
| App isolation | Forge apps run in sandboxed environments, isolated from other apps |
| Egress controls | All outbound network calls are declared and audited by Atlassian |
| Secrets storage | Dedicated encrypted storage for sensitive values |
For full details on Forge security, see Atlassian Forge Security Documentation.
4. What Atlassian's Forge LLM Provides
AI inference is performed by Atlassian's Forge-hosted LLM (currently a Preview feature per Atlassian), running inside Atlassian's infrastructure. It is covered by Atlassian's platform certifications (SOC 2 Type II, ISO 27001 — Atlassian's, not ours) and Atlassian's AI data terms.
Prompts are not sent to any third-party AI provider and are not used to train models. For details, see Atlassian's Forge documentation.
5. What We Don't Have (Transparency)
In the interest of honesty, here's what we don't currently hold:
- SOC 2 Type II certification — Atlassian holds this for the Forge platform the App runs on; we do not hold it at the app level
- ISO 27001 certification — Atlassian holds this for the Forge platform; we do not
- Dedicated security team — we are an independent development team; security is built into our process, not a separate department
- Penetration testing reports — we have not commissioned independent penetration testing
- Bug bounty program — we accept vulnerability reports at security@supertemplates.ai but do not offer monetary rewards
We compensate for this by building on Forge (inheriting Atlassian's infrastructure security), keeping AI inference inside Atlassian's platform via the Forge-hosted LLM, pseudonymizing known Jira user identifiers before AI generation, and being fully transparent about what we do and don't control.
6. Vulnerability Reporting
If you discover a security vulnerability in SuperTemplates, please report it responsibly to security@supertemplates.ai. We will acknowledge receipt within 2 business days and work to address confirmed vulnerabilities promptly. Please do not disclose vulnerabilities publicly until we've had reasonable time to address them.
7. Incident Response
In the event of a security incident affecting customer data, we will notify affected site administrators via email within 72 hours of becoming aware of the incident (GDPR Article 33). Where the breach is likely to result in high risk to individuals, we will also assist administrators in fulfilling their obligation to notify affected data subjects without undue delay (GDPR Article 34). Notifications will include the nature of the incident, data potentially affected, and steps taken to mitigate.
8. CAIQ Lite v4 Self-Assessment
We have completed a self-assessment against the CSA Cloud Controls Matrix (CCM) v4 Consensus Assessments Initiative Questionnaire. The assessment covers 46 controls across 16 security domains with a 95.1% compliance rate.
Security Contact
For security questions or vulnerability reports: security@supertemplates.ai
For privacy-related questions: privacy@supertemplates.ai