1. Summary
Canopy Access Review is a read-only, egress-free Atlassian Forge app. It runs entirely inside Atlassian's cloud: it makes no external network calls, and SR Consulting operates no servers, databases, or third-party services that receive, process, or store your Jira data. There is no vendor-side copy of your data to breach.
That architecture is the core of this security policy — most of the risk surface that a vendor security questionnaire is designed to probe (vendor infrastructure, data transfers, sub-processors, hosting providers, backups held by the vendor) does not exist for this app by design. The sections below describe the controls that do apply: how the app is built and reviewed, how we handle vulnerabilities and security incidents, and how we secure the accounts and systems used to develop and publish it.
This policy complements — and does not replace — the Canopy Access Review Privacy Policy, which describes what data the app reads and stores.