Security / Version 1.0
Small footprint. Explicit controls.
Architecture
AfterIncident uses Atlassian Forge functions, Custom UI, Key-Value and Custom Entity storage, scheduled triggers and asynchronous event queues. It creates native Jira issues rather than maintaining a separate task system. No remote application backend or external secret is required.
Access and data minimization
- Interactive Jira operations run as the current user. Server-side authorization checks protect action, evidence and review mutations.
- Dashboard and candidate results are filtered by the current user's Jira visibility.
- Only project administrators can change configuration or explicitly delete the project's app metadata.
- App storage is installation-scoped. User account identification is separated from domain records for erasure.
- Text lengths, dates, result enums and reference formats are validated. Evidence URLs require HTTPS and cannot contain embedded credentials.
Reliability boundaries
Jira updates are reconciled asynchronously; review scanning is hourly. Creation mutations carry an idempotency identifier. An uncertain Jira creation is not automatically repeated. Recurrence scans produce human-review signals and do not change review results.
Permissions
| Scope | Purpose |
|---|---|
| read:jira-work | Read permitted issues, workflows, links and recurrence candidates. |
| write:jira-work | Create native action issues and restore configured links as the acting user. |
| read:jira-user | Find assignable users and display current Jira identities. |
| storage:app | Persist installation-specific app metadata. |
| report:personal-data | Report stored account identifiers to Atlassian's privacy API. |
Reporting a concern
Email support@callsiq.com with “AfterIncident security” in the subject. Include reproduction steps and impact without sending secrets or accessing another customer's data.
This overview describes implemented controls. It is not a claim of independent security certification, regulatory approval or a completed third-party penetration test.