Obsidian Context Map for Jira Support

Setup, support, privacy, terms, and security information for Obsidian Context Map for Jira.

View the Project on GitHub tndud2505-ops/jira-obsidian-support

Security Policy

Last updated: September 4, 2026

This Security Policy describes how JIRA MINI handles security reports for Obsidian Context Map for Jira.

Architecture and data handling

The App runs on Atlassian Forge and uses Jira permissions approved by a Jira administrator. App-created relationships and layout preferences are stored in Atlassian Forge hosted storage. The App does not operate a separate remote backend for Jira data.

The App requests Jira read access to display work-item context, Jira user read access for permitted display information, Jira write access for user-initiated actions, and Forge app storage access for App-created records and preferences.

Reporting a vulnerability

Send suspected vulnerabilities privately to security@allrightsoftware.com. Include the affected app version, a concise description, reproduction steps, potential impact, and any suggested mitigation. Do not include customer secrets or unrelated personal data.

Do not report vulnerabilities through public GitHub Issues. Please allow JIRA MINI a reasonable opportunity to investigate and coordinate a fix before public disclosure. We aim to acknowledge security reports within two business days during published support hours.

Response process

JIRA MINI will review the report, attempt to reproduce the issue, assess its impact, and coordinate remediation and customer communication when required. Resolution time depends on severity, reproducibility, Atlassian platform dependencies, and release-review requirements.

Scope

Reports should concern Obsidian Context Map for Jira or its published support and policy materials. Atlassian platform vulnerabilities should be reported through Atlassian’s own security channels.