10X Digital
ChangeSafe for Jira
SECURITY

Security Policy

This page describes the security practices, architecture, access model, vulnerability reporting process, and security commitments for ChangeSafe for Jira.

Security-first, read-only design. ChangeSafe for Jira is a read-only Jira administration and custom-field impact analysis app built on Atlassian Forge. It is designed to operate without an external application server, external customer-data database, or external customer-data egress.

1. Security architecture

Atlassian Forge hosted
Application execution uses Atlassian Forge and Jira services.
No external customer-data database
ChangeSafe does not maintain a separate external database of Jira customer data.
No external application server
ChangeSafe does not rely on a separate server operated by 10X Digital for core analysis.
No external customer-data egress
ChangeSafe is designed without intentional transmission of Jira customer data to external infrastructure.

2. Read-only access model

ChangeSafe is designed for pre-change analysis. It requests read-only Jira permissions required to inspect supported field metadata, configuration, dependencies, permissions, and stored issue-value usage.

ChangeSafe does not request Jira configuration write permissions for its supported analysis functionality and does not rename, hide, delete, reconfigure, or otherwise modify Jira custom fields, issues, workflows, screens, filters, dashboards, or projects.

3. Authorization and least privilege

ChangeSafe follows a least-privilege approach. Protected site-level analysis verifies appropriate Jira administrative permission before app-authorized reads are used.

The app's permission model is intended to limit access to the Jira information required for supported impact analysis, planned-action safety checks, evidence generation, and administrative context.

4. Credentials and secrets

ChangeSafe does not require end users to provide Atlassian Personal Access Tokens, API tokens, Atlassian passwords, authentication codes, or shared secrets in order to use the app.

Customers should never send passwords, API tokens, PATs, or authentication codes in support or security reports.

5. Logging

ChangeSafe is designed to avoid intentionally recording Jira issue content or other customer content in application logs. Atlassian Forge may generate technical and operational logs as part of normal platform operation.

6. Vulnerability reporting

If you believe you have discovered a security vulnerability affecting ChangeSafe for Jira, contact 10X Digital using the security contact below.

Security contact
Email: security.changesafe@tennexdigital.com
Suggested subject: ChangeSafe Security

Please include:

  • A clear description of the issue.
  • Steps to reproduce the issue.
  • The affected ChangeSafe feature or workflow.
  • Observed and expected behavior.
  • Any non-sensitive screenshots or technical details that help reproduce the issue.
Do not include unnecessary Jira customer data. Redact screenshots where appropriate and never include passwords, API tokens, PATs, authentication codes, or other secrets.

7. Security response

10X Digital will review reported security issues, assess severity, investigate valid reports, and prioritize remediation based on customer impact and applicable Atlassian Marketplace security requirements.

Security defects that affect Marketplace requirements will be handled in accordance with applicable Atlassian Marketplace security-remediation expectations.

8. Compliance

ChangeSafe currently does not claim independent compliance certifications such as ISO 27001, SOC 2, HIPAA, FedRAMP, or similar certifications.

ChangeSafe's architecture is designed to benefit from Atlassian Forge security controls and to minimize the amount of infrastructure operated directly by 10X Digital.

9. Scope and limitations

This policy covers ChangeSafe for Jira. It does not describe the security posture of unrelated Atlassian products, customer infrastructure, third-party Jira apps, external integrations, or organization-specific scripts and processes.

10. Policy updates

10X Digital may update this Security Policy when ChangeSafe's architecture, security practices, Marketplace requirements, or supported functionality changes.

Last updated: 28 August 2026