VeriReport — Security Policy

Atlassian Forge app · Runs on Atlassian · no external egress

VeriReport is built and operated by Reglyze. This page describes the app's security posture and how to report a vulnerability. For what data the app accesses and stores, see the privacy & data-handling policy.

Platform & architecture

Least privilege

Data protection

Secure development

Reporting a vulnerability

We welcome good-faith security research. If you believe you have found a vulnerability in VeriReport:

Safe harbor: we will not pursue legal action for good-faith, non-disruptive research — do not access data that is not yours, do not degrade the service, and use a test or development site where possible.

Incident response

If a security incident affects customer data, we notify Atlassian and affected customers without undue delay, in accordance with Atlassian Marketplace partner requirements, including the nature of the incident, its impact, and remediation steps.

Compliance

Reglyze does not currently hold independent security certifications. VeriReport runs exclusively on Atlassian's cloud infrastructure, which maintains SOC 2, ISO 27001 and other certifications (see Atlassian compliance); the app introduces no infrastructure outside it.

Contact

Security contact: contact@reglyze.com.