⚡ Project Commander
Features Privacy Security Terms DPA

Security

Last updated: July 22, 2026 — added certifications, sub-processors, uptime, incident response, and security-team Q&A sections

This page describes how Project Commander protects your data. Project Commander is a planning and analysis app for Jira Cloud, built and hosted entirely on the Atlassian Forge platform.

1. Built on Atlassian Forge

Project Commander runs as a Forge app inside Atlassian's own cloud infrastructure. It has no separate servers of its own. This means:

  • The app's code runs in Atlassian's secure, sandboxed Forge runtime
  • The app inherits Atlassian's platform-level security controls, hosting, and compliance posture
  • There is no external backend operated by us where your Jira data could be copied or exposed

2. Data Storage and Isolation

All data the app stores is held in Atlassian Forge storage. It is isolated to your Jira instance and scoped to your Atlassian account.

  • Your Jira data is never copied out. Issues, sprints, and board data are read in real time through Atlassian's secure APIs and are not stored by the app outside Atlassian.
  • App-created content — team capacity settings, risks, action items, retrospective notes, governance policies, portfolio lists, saved plan baselines, velocity history, sprint snapshots, and per-user preferences — is stored in Forge storage and stays within Atlassian.
  • No external database. Project Commander does not use any database or storage service outside Atlassian.

3. Encryption

  • In transit: All communication uses HTTPS/TLS encryption.
  • API keys at rest: If you configure an optional AI provider key, it is stored using Forge's encrypted secret storage, separate from regular app storage, and is only retrieved server-side at the moment an AI request is sent.
  • At rest: All other app data is protected by Atlassian Forge's platform-level encryption of stored data.

4. Access Control and Least Privilege

The app requests only the Jira permissions it needs to do its job — reading sprints, issues, boards, projects, and user display names, and writing sprint and issue changes you make through the app. Access to your data inside the app is governed by your existing Jira permissions: users only see what their Jira account already allows them to see.

5. Data Egress

Project Commander sends data outside Atlassian in only one situation: the optional AI features, and only when you have enabled them by supplying your own AI provider key. When triggered, planning context is sent to the provider you chose (Anthropic, OpenAI, or Google) so it can generate a response. The app does not send issue descriptions, comments, or attachments, and it does not log or retain prompts or responses. There is no analytics, tracking, or telemetry of any kind. If no AI key is configured, no data ever leaves Atlassian. Full details are in our Privacy Policy.

6. Personal Data Handling

Project Commander implements Atlassian's personal-data reporting process. On a regular schedule it reports to Atlassian which Atlassian accounts it holds data for. When Atlassian notifies the app that an account has been closed, the app automatically erases that person's stored data; when an account's details change, the app refreshes them so it does not keep stale copies.

7. Data Retention and Deletion

App data persists until you remove it through the app or uninstall the app. Uninstalling Project Commander deletes everything it stored in Forge storage — configuration, team capacity, velocity history, snapshots, risks, action items, retrospectives, governance and portfolio data, plan baselines, alert dismissals, the AI enrichment cache, and your AI API key.

8. Website and Web App Security

This website applies standard hardening, including a Content Security Policy, clickjacking protection, MIME-type sniffing protection, and a strict referrer policy. The website does not collect personal data.

The web app at projectcommander.app/app is separate from the installed Jira app, and everything else on this page describes the installed app — the web app shares none of its data paths. The web app offers two modes, and to be equally clear about each:

  • Demo mode runs entirely in your browser on generated sample data. It makes no calls to any Jira, creates no account, and stores nothing — every change is discarded when the page reloads.
  • Connect mode (optional) analyzes your own Jira through Atlassian's official sign-in: you approve read-only access on Atlassian's own consent screen, for the one Jira site you choose — no password or token is ever typed into our site. The access grant is kept in your browser for the current tab session only and is gone when the tab closes; Log out wipes it immediately, along with all app data held in the browser. Each request passes through our relay to your Jira and is never stored or logged by us. Sign-ins are recorded only as an irreversible connection code with dates, sign-in counts, and usage counts — no name, email, or site is stored, and the code cannot be turned back into an identity; it exists so we can count distinct connections and disable abusive access. Connect mode cannot change anything in your Jira and acts only with your own Jira account's permissions. You can cut off its access at any time from your Atlassian account's Connected apps page, and a Jira admin can block the app for their whole site.
  • In either mode, the only other outbound call is the optional AI feature: if you supply your own AI provider key, that request passes through our relay to the provider you chose, per request, and is not stored.

9. Certifications and Compliance

Where we are today:

  • SOC 2 Type II — in progress. Independent auditor engaged; target completion date to be confirmed. Contact us for the current audit timeline in writing.
  • ISO 27001 — planned after SOC 2.
  • GDPR — fully compliant. Data lives inside your Jira tenant; we do not transfer personal data out of it. See sub-processor list below.
  • CCPA — compliant, on the same data-handling posture as GDPR.
  • HIPAA — not applicable. Project Commander is not intended for HIPAA-covered workflows.

Where we inherit Atlassian's certifications: Because Project Commander runs on Forge, the underlying infrastructure is covered by Atlassian's own certifications:

  • SOC 2 Type II — Atlassian's Forge platform. Reports available under NDA from Atlassian.
  • ISO 27001, ISO 27017, ISO 27018 — Atlassian's Cloud platform.
  • PCI DSS — Atlassian's Marketplace billing.
  • Underlying cloud infrastructure — AWS (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP).

For enterprise buyers: many accept "runs on Forge, inherits Atlassian's certifications" as sufficient for the data-handling layer, given we don't store data outside your tenant. If SOC 2 completion is a gating requirement for your organization, email us and we'll share our current audit timeline in writing.

10. Sub-processors

The complete list of third parties Project Commander uses:

Sub-processor Purpose Data shared
Atlassian Hosting (Forge), authentication, storage All app data (lives inside your tenant, owned by you)
Anthropic (Claude API) Optional AI narrative summaries and natural-language What-If input Only planning context submitted to AI features; opt-in per project
OpenAI Alternative AI provider Same scope as Anthropic; opt-in
Google Gemini Alternative AI provider Same scope; opt-in

That is the complete list. There is no analytics tracker, no CDN caching your data, no email service reading your data, no logging service outside Atlassian's own. If AI features are disabled for a project, no third-party AI provider is called for that project.

11. Uptime and Reliability

Project Commander runs on Atlassian's Forge platform, so its availability equals Atlassian's availability. Atlassian's public status page: status.atlassian.com.

Since launch there has been no downtime traceable to Project Commander's own code. If a service-affecting incident occurs, it will appear on Atlassian's status page under Forge. We do not schedule maintenance windows on our side; Atlassian owns platform upgrades.

12. Incident Response

If a security incident affects Project Commander or its handling of your data:

  • Detection: automated monitoring on Forge invocation errors and unusual usage patterns.
  • Notification: affected customers notified via email within 72 hours of a confirmed incident, matching GDPR's breach-notification requirement.
  • Investigation: root cause published on this page within 14 days of resolution.
  • Historical record: no security incidents since launch. If that changes, this section will be updated with dated entries.

13. For Your Security Team — Direct Answers

Where does our data go?
Nowhere outside your Jira Cloud tenant, unless you opt into an AI feature (in which case only planning context is sent to Anthropic, OpenAI, or Google for a single API call, retained per that provider's terms).

Can you access our data without permission?
No. Forge storage is isolated per tenant. We cannot read your data from outside your Jira instance.

Does the web app at projectcommander.app/app touch our Jira?
Its demo mode cannot — it runs on generated sample data in the visitor's browser and makes no Jira calls. Its optional connect mode uses Atlassian's official sign-in (OAuth): the user approves read-only access on Atlassian's own consent screen for one chosen site, and can revoke it at any time from their Atlassian account's Connected apps page; the access grant passes through our relay per request and is never stored or logged. See section 8.

What happens if you're breached?
A breach would have to happen inside Atlassian's Forge platform, since that's where all data lives. We'd notify affected customers within 72 hours per GDPR. In practice, an incident affecting your data would be an Atlassian incident.

Do you have SOC 2?
Not our own certification yet — in progress. We run on Atlassian's SOC 2 Type II Forge platform, which many enterprises accept as sufficient.

Do you have a DPA?
Yes — see our Data Processing Agreement. Standard EU-approved terms, GDPR-compliant, sub-processor list matches this page.

Can you complete a security questionnaire?
Yes. SIG Lite, CAIQ, and custom questionnaires completed personally, typical turnaround 5 business days. Email support with the questionnaire attached.

Can we do a penetration test?
Project Commander is a Forge app running in Atlassian's infrastructure. Any pen test would need to conform to Atlassian's rules of engagement. Email us and we'll work with you and Atlassian to structure it.

14. Reporting a Security Issue

We take security reports seriously and will respond promptly. If you believe you have found a vulnerability or have a security concern about Project Commander, please contact us using the details below. Please include enough detail to reproduce the issue, and give us a reasonable opportunity to address it before any public disclosure.

Response commitment for verified vulnerability reports: acknowledgment within 24 hours, validity confirmation within 72 hours, fix ETA within 7 days. We credit reporters in the changelog with their permission.

Security Contact

To report a security issue or ask a security question, email us:

Email: support@projectcommander.app

Project Commander
Privacy Policy Security Terms of Service Data Processing Agreement Support

© 2026 Project Commander. Operated by Donald Salz. Built for Jira Cloud.