Data Storage & Security
Overviewβ
Script Master is a 100% native Atlassian Forge application. All data β including scripts, configurations, and any values stored by the app β lives exclusively within the Atlassian Forge environment on your own cloud instance.
We do not operate any external databases or custom backend infrastructure. Application data (scripts, configuration, logs) never leaves your Atlassian Cloud instance. Usage statistics are collected through Forge's own custom metrics, which stay inside the Atlassian platform β see Usage Metrics below.
What Data Is Stored?β
Script Master stores only the data required for the app to function:
| Data Type | Description |
|---|---|
| Scripts | JavaScript source code written by your administrators |
| App Configuration | Settings configured per product (Jira / Confluence) |
| Execution Logs | Output logs produced during script execution |
| Scheduled Job Definitions | Cron expressions and associated script references |
| Custom Field Definitions | Field type, linked script, and rendering configuration |
| Web Trigger Definitions | Endpoint names and associated script references |
| Tools Configuration | Per-tool access rules for the Tools module: access level and the group names selected for each tool |
| Audit Metadata | For each fragment, gadget, macro, scheduled job, and web trigger: the Atlassian account ID of its creator and last editor, plus the two timestamps β see Audit Metadata |
Apart from the account IDs recorded as audit metadata, no personal user data (such as profile information, credentials, or issue content) is stored by the app. Display names and avatars are resolved from your Atlassian instance at render time and are never persisted. Any Jira or Confluence data accessed via scripts is read in real time through Atlassian APIs and is never persisted by Script Master.
Where Is Data Stored?β
All data is stored using the Atlassian Forge Storage API, which is:
- Hosted entirely within Atlassian's own infrastructure
- Tenant-isolated β your data is never shared with or accessible by other Atlassian customers
- Subject to Atlassian's own security, compliance, and data residency policies
There are no external API calls to Apportunity servers, and no application data (scripts, configurations, or issue/page content) is ever transmitted outside of your Atlassian Cloud instance.
Usage Metricsβ
To understand which features are used and where to invest, the app emits Forge custom metrics β plain counters provided by the Atlassian platform itself, such as "a scheduled job executed" or "a fragment was saved".
- The app no longer uses Google Analytics, Segment, or any other third-party analytics service, and makes no analytics network calls to non-Atlassian hosts.
- Metrics are counters only. They carry a name and an increment β no parameters, dimensions, user identifiers, session identifiers, or free-form values.
- Counters are aggregated by Atlassian and exposed to us as totals in the Forge developer console.
What is NOT collected:
- Content of your Jira issues, Confluence pages, or any other instance data
- User credentials or authentication tokens
- Any personally identifiable information from your Atlassian instance β including user, account, or instance identifiers
Atlassian's Security & Complianceβ
Because Script Master is fully built on the Forge platform, Atlassian is the data processor for any information stored by the app. Your organization's existing agreements and trust relationship with Atlassian cover Script Master data storage.
For detailed information about Atlassian's security posture, certifications, and compliance frameworks, refer to the official Atlassian resources:
- Atlassian Trust Center
- Atlassian Security Practices
- Atlassian Cloud Terms of Service
- Atlassian Privacy Policy
- Forge Platform Overview
Summary for Security Reviewsβ
If your organization is conducting a security review or vendor assessment, the key facts are:
- β 100% Forge-native β no custom backend infrastructure operated by Apportunity
- β No external databases β all application data is stored via Atlassian Forge Storage API
- β Instance content stays in Atlassian Cloud β scripts, configs, and Jira/Confluence content are never transmitted externally
- β Tenant isolation β your data is logically isolated from other tenants by the Forge platform
- β Atlassian is the data processor β covered by your existing Atlassian agreements
- β No third-party analytics β usage is measured with Forge native custom metrics (counters only); no Google Analytics, no Segment, no external analytics endpoints
- βΉοΈ Account IDs in audit metadata β the app stores the Atlassian account ID of the creator and last editor of each configured item; no other user attributes are persisted
For any additional questions, contact us at https://apportunity-apps.atlassian.net/servicedesk/customer/portal/1.