Legal

Security Statement

How we protect your data — and what we rely on others to protect.

Last updated: July 2, 2026

Our approach

We believe in transparency. This page clearly separates what we build and control from what the Atlassian Forge platform provides. We don't claim certifications we don't hold.

1. Architecture

SuperTemplates is built on Atlassian Forge, Atlassian's cloud app platform. This means:

  • No external servers — the App runs entirely on Atlassian's infrastructure
  • No external databases — all persistent data is stored in Forge Key-Value Storage
  • No self-hosted backend — there is no server we operate that stores or processes your Jira data

AI inference runs on Atlassian's Forge-hosted LLM, inside Atlassian's infrastructure — AI prompts never leave the Atlassian platform. The only declared outbound network call from the App is to our analytics provider (PostHog, EU), which site administrators can disable. With analytics disabled, no data is sent outside Atlassian infrastructure.

SuperTemplates is operated by a registered business (działalność gospodarcza) in Poland.

2. What We Build and Control

Security measures implemented by SuperTemplates directly.

Smart Anonymization

Before data is sent to the AI model (Atlassian's Forge-hosted LLM), we automatically pseudonymize known Jira user identifiers — display names from your project's member list are replaced with anonymous codes (e.g., “U1”), and system identifiers such as Atlassian account IDs, email addresses, project keys, and board names are stripped. The model never sees these identifiers. Important: Free-text content you enter in prompts is sent to the model as written. You are responsible for not including sensitive personal data in AI generation prompts.

Minimal Data Access

The App requests only the Jira scopes necessary for its functionality. We never read existing issue content (titles, descriptions, comments, attachments). We access project metadata (issue types, priorities, fields, sprints) only to populate the editor UI.

No API Keys

AI inference is provided by Atlassian's Forge-hosted LLM, authenticated by the Forge platform itself. The App holds no AI provider credentials, so there are no keys to leak, rotate, or manage.

Admin Controls

Site administrators can view per-user usage statistics and disable analytics egress entirely. The App functions normally without analytics.

Code Practices

All code is reviewed before deployment. The App is built on Atlassian Forge, which enforces sandboxed execution and declared egress. Dependencies are regularly audited for known vulnerabilities.

3. What Atlassian Forge Provides

Security measures provided by the Forge platform. We rely on these but do not operate them ourselves.

MeasureDetail
Encryption at restAES-256 via AWS infrastructure
Encryption in transitTLS 1.2+
Data residencyForge storage respects your Atlassian data residency region
App isolationForge apps run in sandboxed environments, isolated from other apps
Egress controlsAll outbound network calls are declared and audited by Atlassian
Secrets storageDedicated encrypted storage for sensitive values

For full details on Forge security, see Atlassian Forge Security Documentation.

4. What Atlassian's Forge LLM Provides

AI inference is performed by Atlassian's Forge-hosted LLM (currently a Preview feature per Atlassian), running inside Atlassian's infrastructure. It is covered by Atlassian's platform certifications (SOC 2 Type II, ISO 27001 — Atlassian's, not ours) and Atlassian's AI data terms.

Prompts are not sent to any third-party AI provider and are not used to train models. For details, see Atlassian's Forge documentation.

5. What We Don't Have (Transparency)

In the interest of honesty, here's what we don't currently hold:

  • SOC 2 Type II certification — Atlassian holds this for the Forge platform the App runs on; we do not hold it at the app level
  • ISO 27001 certification — Atlassian holds this for the Forge platform; we do not
  • Dedicated security team — we are an independent development team; security is built into our process, not a separate department
  • Penetration testing reports — we have not commissioned independent penetration testing
  • Bug bounty program — we accept vulnerability reports at security@supertemplates.ai but do not offer monetary rewards

We compensate for this by building on Forge (inheriting Atlassian's infrastructure security), keeping AI inference inside Atlassian's platform via the Forge-hosted LLM, pseudonymizing known Jira user identifiers before AI generation, and being fully transparent about what we do and don't control.

6. Vulnerability Reporting

If you discover a security vulnerability in SuperTemplates, please report it responsibly to security@supertemplates.ai. We will acknowledge receipt within 2 business days and work to address confirmed vulnerabilities promptly. Please do not disclose vulnerabilities publicly until we've had reasonable time to address them.

7. Incident Response

In the event of a security incident affecting customer data, we will notify affected site administrators via email within 72 hours of becoming aware of the incident (GDPR Article 33). Where the breach is likely to result in high risk to individuals, we will also assist administrators in fulfilling their obligation to notify affected data subjects without undue delay (GDPR Article 34). Notifications will include the nature of the incident, data potentially affected, and steps taken to mitigate.

8. CAIQ Lite v4 Self-Assessment

We have completed a self-assessment against the CSA Cloud Controls Matrix (CCM) v4 Consensus Assessments Initiative Questionnaire. The assessment covers 46 controls across 16 security domains with a 95.1% compliance rate.

Security Contact

For security questions or vulnerability reports: security@supertemplates.ai

For privacy-related questions: privacy@supertemplates.ai