Last updated: July 22, 2026 — added certifications, sub-processors, uptime, incident response, and security-team Q&A sections
This page describes how Project Commander protects your data. Project Commander is a planning and analysis app for Jira Cloud, built and hosted entirely on the Atlassian Forge platform.
Project Commander runs as a Forge app inside Atlassian's own cloud infrastructure. It has no separate servers of its own. This means:
All data the app stores is held in Atlassian Forge storage. It is isolated to your Jira instance and scoped to your Atlassian account.
The app requests only the Jira permissions it needs to do its job — reading sprints, issues, boards, projects, and user display names, and writing sprint and issue changes you make through the app. Access to your data inside the app is governed by your existing Jira permissions: users only see what their Jira account already allows them to see.
Project Commander sends data outside Atlassian in only one situation: the optional AI features, and only when you have enabled them by supplying your own AI provider key. When triggered, planning context is sent to the provider you chose (Anthropic, OpenAI, or Google) so it can generate a response. The app does not send issue descriptions, comments, or attachments, and it does not log or retain prompts or responses. There is no analytics, tracking, or telemetry of any kind. If no AI key is configured, no data ever leaves Atlassian. Full details are in our Privacy Policy.
Project Commander implements Atlassian's personal-data reporting process. On a regular schedule it reports to Atlassian which Atlassian accounts it holds data for. When Atlassian notifies the app that an account has been closed, the app automatically erases that person's stored data; when an account's details change, the app refreshes them so it does not keep stale copies.
App data persists until you remove it through the app or uninstall the app. Uninstalling Project Commander deletes everything it stored in Forge storage — configuration, team capacity, velocity history, snapshots, risks, action items, retrospectives, governance and portfolio data, plan baselines, alert dismissals, the AI enrichment cache, and your AI API key.
This website applies standard hardening, including a Content Security Policy, clickjacking protection, MIME-type sniffing protection, and a strict referrer policy. The website does not collect personal data.
The web app at projectcommander.app/app is separate from the installed Jira app, and everything else on this page describes the installed app — the web app shares none of its data paths. The web app offers two modes, and to be equally clear about each:
Where we are today:
Where we inherit Atlassian's certifications: Because Project Commander runs on Forge, the underlying infrastructure is covered by Atlassian's own certifications:
For enterprise buyers: many accept "runs on Forge, inherits Atlassian's certifications" as sufficient for the data-handling layer, given we don't store data outside your tenant. If SOC 2 completion is a gating requirement for your organization, email us and we'll share our current audit timeline in writing.
The complete list of third parties Project Commander uses:
| Sub-processor | Purpose | Data shared |
|---|---|---|
| Atlassian | Hosting (Forge), authentication, storage | All app data (lives inside your tenant, owned by you) |
| Anthropic (Claude API) | Optional AI narrative summaries and natural-language What-If input | Only planning context submitted to AI features; opt-in per project |
| OpenAI | Alternative AI provider | Same scope as Anthropic; opt-in |
| Google Gemini | Alternative AI provider | Same scope; opt-in |
That is the complete list. There is no analytics tracker, no CDN caching your data, no email service reading your data, no logging service outside Atlassian's own. If AI features are disabled for a project, no third-party AI provider is called for that project.
Project Commander runs on Atlassian's Forge platform, so its availability equals Atlassian's availability. Atlassian's public status page: status.atlassian.com.
Since launch there has been no downtime traceable to Project Commander's own code. If a service-affecting incident occurs, it will appear on Atlassian's status page under Forge. We do not schedule maintenance windows on our side; Atlassian owns platform upgrades.
If a security incident affects Project Commander or its handling of your data:
Where does our data go?
Nowhere outside your Jira Cloud tenant, unless you opt into an AI feature (in which case only planning context is sent to Anthropic, OpenAI, or Google for a single API call, retained per that provider's terms).
Can you access our data without permission?
No. Forge storage is isolated per tenant. We cannot read your data from outside your Jira instance.
Does the web app at projectcommander.app/app touch our Jira?
Its demo mode cannot — it runs on generated sample data in the visitor's browser and makes no Jira calls. Its optional connect mode uses Atlassian's official sign-in (OAuth): the user approves read-only access on Atlassian's own consent screen for one chosen site, and can revoke it at any time from their Atlassian account's Connected apps page; the access grant passes through our relay per request and is never stored or logged. See section 8.
What happens if you're breached?
A breach would have to happen inside Atlassian's Forge platform, since that's where all data lives. We'd notify affected customers within 72 hours per GDPR. In practice, an incident affecting your data would be an Atlassian incident.
Do you have SOC 2?
Not our own certification yet — in progress. We run on Atlassian's SOC 2 Type II Forge platform, which many enterprises accept as sufficient.
Do you have a DPA?
Yes — see our Data Processing Agreement. Standard EU-approved terms, GDPR-compliant, sub-processor list matches this page.
Can you complete a security questionnaire?
Yes. SIG Lite, CAIQ, and custom questionnaires completed personally, typical turnaround 5 business days. Email support with the questionnaire attached.
Can we do a penetration test?
Project Commander is a Forge app running in Atlassian's infrastructure. Any pen test would need to conform to Atlassian's rules of engagement. Email us and we'll work with you and Atlassian to structure it.
We take security reports seriously and will respond promptly. If you believe you have found a vulnerability or have a security concern about Project Commander, please contact us using the details below. Please include enough detail to reproduce the issue, and give us a reasonable opportunity to address it before any public disclosure.
Response commitment for verified vulnerability reports: acknowledgment within 24 hours, validity confirmation within 72 hours, fix ETA within 7 days. We credit reporters in the changelog with their permission.
To report a security issue or ask a security question, email us:
Email: support@projectcommander.app