Security
Security and privacy are built into the fabric of our app, infrastructure, processes and services, so you can rest assured that your data is always protected. Your data never leaves your site.
Atlassian Cloud Fortified
Our reliability and support are certified Cloud Fortified by Atlassian
Read moreAtlassian Ecoscanner
Our apps are scanned by the Ecoscanner Platform (Cloud) and Security Scanner (Data Center)
Read moreBug bounty program
Over 100 security researchers scan our apps regularly for vulnerabilities
Read moreYour data never leaves your site
We don't access and store any customer data externally, all data is stored in your Jira site
Principle of least privilege
JXL only requests access scopes actually required to perform its functionality, nothing more
Vulnerability management
We apply accelerated resolution timeframes in the event of necessary security bugfixes
Read moreGDPR compliant
Our apps are compliant with EU regulation 2016/679 and all other applicable data protection laws
CAIQ-Lite
Publicly available Cloud Security Alliance Consensus Assessments Initiative Questionnaire
Download questionnaireSecurity posture questionnaires
We are open to prioritising work on any custom questionnaires you might need filled in
security@fine.softwareJXL enables users to display and edit their Jira data (i.e., data to which they have read and/or write access) via the application's user interface. To do so, JXL, running in the user's browser, invokes the Jira REST API (either directly, or in JXL for Jira Cloud also sometimes indirectly through gateway services operated by Fine Software) based on the user's input. The Jira REST API respects the signed-in user's, as well as the app's, permissions. No Jira data is ever loaded, created, updated, deleted, or otherwise manipulated in a way that has not been initiated by the user, or does not respect the permission model of the Jira site.
JXL stores its sheets data, along with various user-level information (such as the most recently visited sheets), directly in the customer's Jira site. This means that all customer data is stored by Jira, and therefore subject to all security measures and data residency management Atlassian provides (JXL for Jira Cloud), or the customer operates (JXL for Jira Data Center and Server).
All data transfer between the user's browser and the user's Jira site happens securely via HTTPS.
With all customer data being stored in Jira, JXL utilises Atlassian's backup and data recovery features (JXL for Jira Cloud), or equivalent capabilities that the customer operates (JXL for Jira Data Center and Server).
As all data are exchanged directly between the customer's Jira site and the user's browser, no Fine Software employee, regardless of their role, has access to customer data at rest. Application logs are anonymised and don't contain any references to customer data.
Please refer to our Privacy policy for a list of subcontractors.
We commit to the Accelerated Resolution Timeframes of Atlassian's security bugfix policy and to our Service level agreement.