Skip to main content

Data Storage & Security

Overview​

Script Master is a 100% native Atlassian Forge application. All data β€” including scripts, configurations, and any values stored by the app β€” lives exclusively within the Atlassian Forge environment on your own cloud instance.

We do not operate any external databases or custom backend infrastructure. Application data (scripts, configuration, logs) never leaves your Atlassian Cloud instance. Usage statistics are collected through Forge's own custom metrics, which stay inside the Atlassian platform β€” see Usage Metrics below.


What Data Is Stored?​

Script Master stores only the data required for the app to function:

Data TypeDescription
ScriptsJavaScript source code written by your administrators
App ConfigurationSettings configured per product (Jira / Confluence)
Execution LogsOutput logs produced during script execution
Scheduled Job DefinitionsCron expressions and associated script references
Custom Field DefinitionsField type, linked script, and rendering configuration
Web Trigger DefinitionsEndpoint names and associated script references
Tools ConfigurationPer-tool access rules for the Tools module: access level and the group names selected for each tool
Audit MetadataFor each fragment, gadget, macro, scheduled job, and web trigger: the Atlassian account ID of its creator and last editor, plus the two timestamps β€” see Audit Metadata

Apart from the account IDs recorded as audit metadata, no personal user data (such as profile information, credentials, or issue content) is stored by the app. Display names and avatars are resolved from your Atlassian instance at render time and are never persisted. Any Jira or Confluence data accessed via scripts is read in real time through Atlassian APIs and is never persisted by Script Master.


Where Is Data Stored?​

All data is stored using the Atlassian Forge Storage API, which is:

  • Hosted entirely within Atlassian's own infrastructure
  • Tenant-isolated β€” your data is never shared with or accessible by other Atlassian customers
  • Subject to Atlassian's own security, compliance, and data residency policies

There are no external API calls to Apportunity servers, and no application data (scripts, configurations, or issue/page content) is ever transmitted outside of your Atlassian Cloud instance.


Usage Metrics​

To understand which features are used and where to invest, the app emits Forge custom metrics β€” plain counters provided by the Atlassian platform itself, such as "a scheduled job executed" or "a fragment was saved".

  • The app no longer uses Google Analytics, Segment, or any other third-party analytics service, and makes no analytics network calls to non-Atlassian hosts.
  • Metrics are counters only. They carry a name and an increment β€” no parameters, dimensions, user identifiers, session identifiers, or free-form values.
  • Counters are aggregated by Atlassian and exposed to us as totals in the Forge developer console.

What is NOT collected:

  • Content of your Jira issues, Confluence pages, or any other instance data
  • User credentials or authentication tokens
  • Any personally identifiable information from your Atlassian instance β€” including user, account, or instance identifiers

Atlassian's Security & Compliance​

Because Script Master is fully built on the Forge platform, Atlassian is the data processor for any information stored by the app. Your organization's existing agreements and trust relationship with Atlassian cover Script Master data storage.

For detailed information about Atlassian's security posture, certifications, and compliance frameworks, refer to the official Atlassian resources:


Summary for Security Reviews​

If your organization is conducting a security review or vendor assessment, the key facts are:

  • βœ… 100% Forge-native β€” no custom backend infrastructure operated by Apportunity
  • βœ… No external databases β€” all application data is stored via Atlassian Forge Storage API
  • βœ… Instance content stays in Atlassian Cloud β€” scripts, configs, and Jira/Confluence content are never transmitted externally
  • βœ… Tenant isolation β€” your data is logically isolated from other tenants by the Forge platform
  • βœ… Atlassian is the data processor β€” covered by your existing Atlassian agreements
  • βœ… No third-party analytics β€” usage is measured with Forge native custom metrics (counters only); no Google Analytics, no Segment, no external analytics endpoints
  • ℹ️ Account IDs in audit metadata β€” the app stores the Atlassian account ID of the creator and last editor of each configured item; no other user attributes are persisted

For any additional questions, contact us at https://apportunity-apps.atlassian.net/servicedesk/customer/portal/1.