Security

A practical approach to application security

PezTech Software designs applications around least-privilege access and minimising the data required to provide each product's functionality.

Data minimisation

Products are designed to access and retain only the information required for their documented functionality. Bulk Approvals for JSM uses Atlassian Forge and does not copy Jira request or approval data to a separate PezTech-operated backend or database.

Authentication

Bulk Approvals uses the signed-in Jira user and Jira remains authoritative for request visibility and approval authorisation. The app does not require a customer personal access token or API token.

Credential handling

Passwords, credentials and API tokens should never be sent to PezTech Software by email.

Application permissions

Application permissions are intended to be limited to those required for the product to work. Final Marketplace privacy and security disclosures will identify the production scopes before release.

Dependency management

Application dependencies are kept deliberate and reviewed as part of product maintenance. Detailed operational disclosures will accompany the Marketplace release material.

Vulnerability reporting

Report a suspected security or privacy issue to support@peztechsoftware.co.uk with a clear description and steps to reproduce it. Do not include credentials, Jira request content or information you are not authorised to share.