Security
Flokker apps are built on Atlassian Forge and run entirely within Atlassian’s cloud. This shapes our security posture in a few important ways.
Key points
- Your data stays in Atlassian’s cloud. App data is stored in Jira (for Connected Table, in the issue’s own field value). Nothing is sent to, hosted by, or processed on external servers operated by Flokker.
- No third-party data hosting or database. There is no separate backend to breach; the app runs on Atlassian-managed infrastructure and in the user’s browser.
- Least-privilege permissions. Apps request only the Atlassian scopes they need, which administrators review and approve at install and on any change.
- Data residency & compliance inherit from the Atlassian Forge platform. See Atlassian’s platform documentation and trust resources for the underlying certifications and controls.
For a detailed, feature-level explanation of where data is stored and what the app can access, see How it works: data, storage & security.
Reporting a security issue
If you believe you’ve found a security vulnerability in a Flokker app, please email info@flokker.app with the details. Do not disclose it publicly until we’ve had a chance to investigate and respond.