SECURITY & TRUST

Security & Trust

SprintUnity runs inside Jira Cloud and works directly with the project data you already have there — no separate account, and no separate copy of your data to secure.

⛨ Access controlled by role ⛨ No separate password ⛨ Jira-native

Your data stays in Jira.

SprintUnity is Jira-native — it reads and works with your existing sprints, issues and story points inside Jira. It doesn't require a separate account, a separate login, or a separate store of your data outside Jira.

Runs inside Jira CloudNo separate server for your data to live on

How access is controlled

Sign-in through Jira

SprintUnity doesn't have its own password. Access follows your existing Jira Cloud / Atlassian account sign-in.

Configurable roles

Role-Based Access lets admins define roles for the team, instead of everyone getting the same access.

Suggested role templates

Start from a suggested role template and adjust it, rather than building every role from scratch.

Granular permission grants

Permissions are granted per role — nothing is open by default beyond what a role explicitly allows.

Per-user overrides

Individual users can be granted or restricted access beyond their role, when a team needs an exception.

Full activity trail

Every change to a role or permission is recorded in an activity trail, so admins can see who changed what.

Data & access

Works with your existing Jira data

No separate copy of your sprints, issues or story points — SprintUnity reads and works with what's already in Jira.

Access controlled by role

What a person can see and do in SprintUnity is governed by the role and permissions they've been granted.

Every permission change is logged

Role and permission changes are captured in the activity trail — not silent, not untracked.

How we handle security issues & incidents

Report a concern

If you believe you've found a security issue in SprintUnity, email Admin@Sprintunity.com with details and, if possible, steps to reproduce. We treat every report as confidential.

Acknowledgement & triage

Reports are acknowledged within 2 business days. We assess severity and impact before deciding on a remediation timeline, prioritizing issues that affect customer data or access control first.

Fix & disclosure

Confirmed issues are fixed and deployed as a priority. If an incident is found to have affected customer data, impacted customers are notified directly once the issue is contained.

Vulnerability management

Built on Atlassian Forge

SprintUnity's in-Jira experience runs on Atlassian's Forge platform, so it inherits Forge's own hosting, runtime sandboxing, and infrastructure patching rather than us managing that layer ourselves.

Dependency updates

Third-party libraries used by SprintUnity are kept up to date, and known vulnerabilities in dependencies are patched and redeployed as they're identified.

Reviewed before release

Code changes go through review before being deployed to production, and fixes for reported vulnerabilities are prioritized ahead of new feature work.

General security controls

Encrypted in transit

All traffic between Jira, SprintUnity, and any supporting services is encrypted over HTTPS/TLS. Nothing is sent in plaintext.

Tenant-isolated data

Each Jira site's data is scoped to that tenant. One customer's sprint, issue, and evaluation data is never accessible from another customer's account.

No separate password to steal

SprintUnity has no password of its own — access is always through your existing Jira Cloud sign-in, so there's no separate credential store for SprintUnity accounts to be compromised.

Role-based access

What a user can see and do is governed by the role and permissions an admin has granted them, following the principle of least privilege rather than open-by-default access.

Least-privilege internal access

Internal access to production systems and data is limited to what's needed to operate and support SprintUnity, not open to the whole team by default.

Audit trail

Changes to roles and permissions are recorded in an activity trail, so admins can see who changed what and when.

Where your data is processed.

The core SprintUnity experience runs entirely inside Atlassian's Forge platform alongside your Jira data. A small number of features — Team Evaluation, Reports, and Contribution Analysis — call a supporting backend service to calculate and store the evaluation records those features need. That connection is encrypted end-to-end, and the service only holds the data required to power those specific features. We don't sell your data, and we don't use it for advertising or unrelated analytics.

Encrypted, purpose-limitedOnly used for the features that need it

Data retention & deletion

Retained only while in use

Data is kept only for as long as needed to provide SprintUnity's features to your team — nothing is retained beyond that.

Removed on uninstall

When SprintUnity is uninstalled from a Jira site, data associated with that site is deleted from our systems within 30 days.

Deletion on request

You can request deletion of your site's data at any time by emailing Admin@Sprintunity.com — you don't need to wait for an uninstall.

Responsible disclosure.

We welcome reports from security researchers. If you test SprintUnity in good faith — avoiding data destruction, privacy violations, and service disruption to other customers — and report what you find to Admin@Sprintunity.com before disclosing it publicly, we won't pursue legal action over that research. We ask for a reasonable window to investigate and fix confirmed issues before public disclosure.

Good-faith research welcomeReport privately, we'll respond and fix
🔒

Have more questions?

Reach out to the team for any security or access-related questions.