Every Jira admin knows the email. A team has found “the perfect app,” they need it live by Friday, and somewhere between their request and the install button sits you — and a security questionnaire with more rows than the spreadsheet the app is meant to replace. Where does our data go? Who can read it? Which sub-processors touch it? Can we keep it in our region? The team sees a friendly “Try it free.” You see six weeks of email with a vendor’s security alias.
It isn’t paranoia. Every third-party app you approve becomes part of your attack surface, part of your audit scope, and part of the story you tell when compliance comes knocking. The instinct to slow down and ask hard questions is the right one. The trouble is that, with most apps, the honest answer to “where does our data go?” is “to a server you’ve never seen, governed by a policy you have to take on faith.”
This is exactly the friction the Atlassian Runs on Atlassian program was built to remove — and it’s why we built Advanced Release Planning & Management for Jira, our app for release planning in Jira, on Atlassian’s Forge platform. Forge changes the security conversation from “trust this vendor’s promises” to “read this architecture.” Here is what that means when the questionnaire lands on your desk.
Your data never leaves Atlassian
A Forge app runs on Atlassian-hosted compute and storage, not on infrastructure a vendor rents and manages on the side. The same engine your delivery leads rely on for probabilistic release forecasting runs inside Atlassian’s environment, beside your Jira data — not shipped out to a third-party box for processing. Forge apps cannot make outbound network calls unless those destinations are declared in the app manifest, and ours declares none for your issue data. No egress means there is no quiet data pipeline for procurement to chase down, and nothing to add to your list of external sub-processors.
One tenant can never see another
Multi-tenancy is where admins rightly get nervous. Forge runs every app invocation inside an isolated runtime, and Atlassian’s Tenant Context Service scopes each request to a single customer “container,” so one site’s data cannot bleed into another’s. We don’t operate a shared database of everyone’s releases; your plan exists only in your tenant’s storage. That isolation is enforced by the platform itself, not by a clause in our terms of service — which means it holds even if we make a mistake.
The app only asks for what it needs
Open the install screen and you’ll see exactly which permission scopes the app requests, written in plain language. Forge scopes follow a least-privilege model: an app declares the minimum set of OAuth scopes it needs to function, and administrators review that list before anything is granted. There is no vague “this app can access your account.” You can read the justification for each scope, match it to a feature you actually want, and grant access deliberately rather than blindly. If a scope can’t be tied to a capability, that’s your signal to ask why.
Data residency travels with your site
If your Jira data is pinned to a region for compliance, a Forge app’s hosted storage honors the same data residency. Atlassian handles the hosting, pinning, and migration of that data between supported locations, so the app inherits your residency posture instead of forcing a separate negotiation. You don’t have to file a fresh request or cross-check a vendor’s data-center map against your obligations — residency is a property the app picks up from your Atlassian site.
The questionnaire is already half-answered
Because these controls are structural, much of your review is done before you start. Our Marketplace listing carries a completed Data Security Self-Assessment and Data Security Statement, so the answers to “encryption in transit and at rest,” “data retention,” and “where is it processed” aren’t ours to invent — they rest on Atlassian’s platform guarantees, documented and linkable. You can read how our security posture works in our docs and attach it straight to your review packet.
The result is the rarest thing in app procurement: a short conversation. The review that used to take six weeks becomes an afternoon, because the answers aren’t marketing copy — they’re properties of the same platform your team already trusts to run Jira itself. You get to say “yes” faster, and you get to say it with evidence instead of optimism.
See it for yourself
Read the Data Security Statement on our Atlassian Marketplace listing and install Advanced Release Planning free for 30 days — no data leaves your tenant to find out whether it fits. For the bigger picture on how the app helps your teams plan, browse our release planning guides and resources.




Leave a Reply
Your email is safe with us.