Security / Version 1.0

Small footprint. Explicit controls.

Architecture

AfterIncident uses Atlassian Forge functions, Custom UI, Key-Value and Custom Entity storage, scheduled triggers and asynchronous event queues. It creates native Jira issues rather than maintaining a separate task system. No remote application backend or external secret is required.

Access and data minimization

Reliability boundaries

Jira updates are reconciled asynchronously; review scanning is hourly. Creation mutations carry an idempotency identifier. An uncertain Jira creation is not automatically repeated. Recurrence scans produce human-review signals and do not change review results.

Permissions

ScopePurpose
read:jira-workRead permitted issues, workflows, links and recurrence candidates.
write:jira-workCreate native action issues and restore configured links as the acting user.
read:jira-userFind assignable users and display current Jira identities.
storage:appPersist installation-specific app metadata.
report:personal-dataReport stored account identifiers to Atlassian's privacy API.

Reporting a concern

Email support@callsiq.com with “AfterIncident security” in the subject. Include reproduction steps and impact without sending secrets or accessing another customer's data.

This overview describes implemented controls. It is not a claim of independent security certification, regulatory approval or a completed third-party penetration test.