Plugin Vault Logo

Plugin Vault Security Policy

Last Updated: January 23, 2025


Scope

This Security Policy applies to all products developed by Plugin Vault for the Atlassian Marketplace, including Mention Groups. It ensures compliance with industry standards, such as GDPR, CCPA, and Canadian privacy regulations, as well as adherence to Atlassian's security and data handling requirements.


1. Data Handling


2. Authentication and Permissions


3. Secure Development Lifecycle

Plugin Vault follows a structured Secure Development Lifecycle (SDLC):


4. Code Reviews and Vulnerability Assessments

All code undergoes peer review to ensure quality and security. Automated tools are employed to identify vulnerabilities, and plugins are periodically reviewed to ensure compliance with Atlassian's security updates.


5. Compliance with Regulations

Plugin Vault adheres to GDPR, CCPA, and Canadian privacy laws, ensuring transparency in data usage and offering rights such as access, correction, and deletion of personal data.


6. Incident Management

Plugin Vault maintains an effective incident response plan:


7. Third-Party Integrations

Plugin Vault apps currently do not integrate with third-party services. All functionality is built upon Atlassian's APIs, ensuring security and reliability.


8. User Communication

Users are informed about security features and data policies: