Security Statement

Security by design, not as a footnote.

Product Delivery Health is built on Atlassian Forge. It reads Jira data within your instance, stores limited app data in Forge Storage, and sends no customer data outside Atlassian's infrastructure.

Forge-native

  • Runs on Atlassian Forge
  • No Baking Dog servers
  • No external databases

Read-only Jira access

  • Reads boards, sprints and issues
  • Does not create Jira issues
  • Does not modify or delete Jira data

No data egress

  • No telemetry
  • No tracking pixels
  • No third-party APIs

1. Platform & Infrastructure

Product Delivery Health is a Forge-native application. All compute, storage, and runtime execution occurs within Atlassian's managed Forge infrastructure.

Baking Dog does not operate any servers, databases, or cloud infrastructure in connection with this app.

Atlassian Forge provides platform-level security, isolation, and compliance controls. Users operating in regulated industries should refer to Atlassian's Trust & Security documentation for details.

2. Data Access

2.1 Jira Data — Read-Only

The app accesses Jira data exclusively via standard Atlassian Forge APIs. Access is scoped to the permissions of the authenticated user — the app cannot access boards, sprints, or issues the user cannot already see in Jira.

The app has read-only access. It does not create, modify, or delete any Jira data.

Data fetched from Jira is used solely to render the dashboard and is not persisted beyond the user's active session.

2.2 Forge Storage

The app uses Atlassian Forge Storage to persist limited app data:

  • Focus Notes: short personal notes, scoped per user per board and visible only to the user who created them.
  • Selected board preference: the last board selected by the user, stored as a user-specific preference.
  • Roadmap entries: visual timeline items created for a board, scoped per board and visible/editable by users who have access to that board through Jira and the app.
All Forge Storage data remains within Atlassian's infrastructure at all times. Baking Dog does not operate external databases or servers for this app, and app data is not transmitted to Baking Dog systems or third-party services.

3. Data Transmission & Third Parties

The app does not transmit customer data outside of Atlassian's infrastructure.

  • No data is sent to Baking Dog's systems.
  • No third-party analytics, monitoring, or telemetry services are used.
  • No external APIs or webhooks are called.
  • No advertising networks or tracking pixels are present inside the app.
  • Atlassian serves as the sole infrastructure sub-processor by providing the Forge platform.

4. Authentication & Authorization

Authentication is handled entirely by Atlassian. Users access the app through their existing Atlassian account. No separate login, password, or credential is required or stored by Baking Dog.

The app operates under the principle of least privilege and requests only the Forge API scopes necessary to read sprint, backlog, and issue data from Jira.

5. Vulnerability Management

The app is submitted through the Atlassian Marketplace review process, which includes automated vulnerability scanning of the app package. Baking Dog monitors for security issues and will release patches promptly if a vulnerability is identified.

Security disclosures can be reported to: support@bakingdog.com

Baking Dog follows a responsible disclosure process. Security researchers are encouraged to report vulnerabilities in good faith. Reports will be acknowledged and investigated promptly.

6. Incident Response

In the unlikely event of a security incident affecting user data stored in Forge Storage, Baking Dog will notify affected users via the contact information associated with their Atlassian account within 72 hours of becoming aware of the incident, in accordance with applicable data protection regulations.

7. Compliance

Product Delivery Health does not independently seek certifications such as SOC 2 or ISO 27001 as a standalone vendor. However, by virtue of running entirely on Atlassian Forge, the app inherits Atlassian's platform-level compliance posture.

The app's data practices are consistent with GDPR requirements applicable to a Forge-native, no-egress application. No personal data is transferred outside the Atlassian platform.

8. Contact

For security-related questions or disclosures, please contact:

Email: support@bakingdog.com
Website: bakingdog.com

Download PDF version

Safe to try on your Jira board.

No external servers. No telemetry. Read-only Jira access.

Try it free in Jira