Security
Security
Last updated: 26 August 2026. This is a concise product security summary, not a compliance certification or a guarantee of risk-free operation.
Current safeguards
- Forge permission:
read:jira-workis used to read Jira data as the signed-in user; the app does not write Jira data. - Explicit processing modes: deterministic generation is the default; AI requires an explicit selection.
- Customer-data boundary: customer AI excludes issue descriptions and caller-supplied Markdown; it sends only structured issue keys, summaries, and grouping fields to OpenAI. Technical mode requires the in-app confirmation before descriptions may be included.
- Validation and bounded execution: inputs are validated, deterministic issue selection is capped at 200 issues per generation, AI-assisted rewriting is capped at 100 issues, and execution is subject to timeouts and Forge quotas.
- Fallback: when AI is unavailable or a quota is reached, deterministic generation remains available rather than silently switching modes.
Residual limitations
Quota counters and reservations are best effort under concurrency; a failed reservation can still affect an allowance. Generated text is a draft and must be reviewed. Prompt-injection defenses are not perfect: Jira text may contain adversarial instructions, so users should inspect output and avoid treating generated prose as authoritative. No security control removes the need for sensible Jira permissions and organizational review.
Reporting a concern
Please report suspected security or privacy issues to info@lucapalonca.com. Include only the minimum reproducible detail and do not send secrets or unnecessary customer data.
Privacy · AI and data processing · Support · Draft terms / EULA