VeriReport — Privacy & Data Handling
VeriReport is an Atlassian Forge app that runs entirely on Atlassian's infrastructure (“Runs on Atlassian”). It is designed so that no customer data leaves the Atlassian cloud — the app declares no external egress.
What the app accesses
-
Jira / Jira Service Management issues in the project where the app is opened,
read via the Forge product APIs using the app's granted scopes
(
read:jira-work,read:servicedesk-request). It reads only the fields needed to compute service-review metrics: created/resolved dates and priority, and — on JSM service-desk projects — SLA cycles, CSAT feedback, and request type. - It does not read issue descriptions, comments, attachments, or other personal data beyond the metric inputs above.
What the app stores
Stored in Forge KVS (Atlassian-hosted storage, scoped to the app installation):
- Generated reports — the computed metrics and the AI-written narrative, per project and month.
- Branding settings — per project: brand name, client name, accent colour, tone, language, and an optional logo image you upload.
Nothing is stored outside Atlassian.
AI narrative
The narrative is generated by Atlassian-hosted Claude via the Forge LLMs API. The prompt contains only the verified, code-computed numbers — never raw issue content — and the model is instructed to use only those numbers. The request stays within Atlassian's infrastructure and is not used to train models.
Data residency & retention
- Data residency follows your Atlassian instance and Forge (EU data residency supported).
- Reports and branding persist in Forge KVS until overwritten (re-generating a month replaces that report) or until the app is uninstalled, which removes the app's stored data.
Third parties
None. The app makes no calls to any non-Atlassian service.
Contact
For privacy questions, contact the app vendor via the Atlassian Marketplace listing.