Architecture and access
ReleaseLint runs on Atlassian Forge. It calls Jira as the current user, requests the single read-only read:jira-work scope, persists no Jira content, defines no publisher remote or external egress, and uses no advertising analytics or artificial-intelligence service.
Application controls
Inputs are allowlisted and resource identifiers are checked against Jira-visible data. Jira text is rendered as text. CSV exports quote fields and neutralize spreadsheet-formula prefixes. Application error logs omit Jira content, account identifiers, tokens and raw response bodies.
Security assurance
Dependency audits and source checks are repeated before releases. ReleaseLint does not claim an independent certification, penetration-test report, SOC 2, ISO 27001, Cloud Fortified status or bug-bounty participation.
Report a vulnerability
Use the private vulnerability reporting form. Do not disclose a suspected vulnerability in a public issue. Do not include customer Jira content, credentials or tokens unless a secure follow-up channel has been agreed.