Security and data handling
IssueMesh moves only what each side chose to share, and keeps only what it needs to keep two issues in sync.
What leaves your Jira
- Nothing, until you decide. Installing IssueMesh synchronizes nothing. A Jira admin enables spaces, and a space admin pairs a space and chooses what it sends.
- Change notifications carry no content. When an issue changes, the app tells the Hub only which issue changed and when. Notifications from spaces that are not enabled are dropped inside your Jira.
- Only shared fields travel. The Hub reads the changed issue with the app's access and passes on only the fields your space shares.
- Internal comments never leave. Internal notes of Jira Service Management and comments restricted to a role or group are never shared.
- E-mail addresses are invisible. The app's access does not include users' e-mail addresses.
What the IssueMesh Hub keeps
| Data | Why |
|---|---|
| Site address, organization name, the list of enabled spaces | to know your site and what it allows |
| The app's access token, encrypted with a key of its own that is sealed with a master key | to read and write your Jira on behalf of the app; deleted when the app is uninstalled |
| Pairings and every saved version of each side's settings, with the Atlassian account ID of the person who saved it; people mappings (account IDs) | to synchronize as configured and to trace who changed what |
| For each synchronized pair: the IDs and keys of both issues and the last synchronized values of the shared fields (which may include text such as summary and description, and account IDs of people fields) | to detect what changed and to resolve conflicts |
| A log of synchronization operations, including the values written, and an audit trail of pairing and settings changes with the acting person's account ID | traceability and support |
| For the review of existing issues: key, shared summary and type of issues awaiting a decision | to let the receiving admin decide |
| For comments and attachments: IDs, a fingerprint of each comment copy, file names and sizes | to avoid duplicates - comment texts and files are not kept |
| A journal of change notifications (IDs and times only) | to process each change once; deleted after 30 days |
The Hub never stores fields you do not share, the content of change events, comment texts or files. Files are streamed from one Jira to the other.
Retention: [retention periods for synchronized values, operations and the audit trail - to be decided]. On request we delete the data of your site.
How access is protected
- Every call is signed by Atlassian. Each request from the app carries a token signed by Atlassian that names the app, the installation and the site. The Hub verifies it and refuses anything that does not match the registered installation.
- Tokens stay with their site. Each installation's access token can be used only against that installation's own Jira.
- Permissions are checked by the Hub with the acting person's identity: changing a pairing or a setting requires administering the space in your Jira.
- Operators cannot change what you synchronize. The team running the Hub sees configurations read-only to diagnose problems. In an emergency it can disable a pairing, which both sides see.
- Encrypted transport. All traffic between the app, the Hub and Jira uses HTTPS.
Where the Hub runs
The IssueMesh Hub runs at gateway.issuemesh.com, hosted by Hetzner Online GmbH in EU data centers (Germany, Finland). Traffic to the Hub passes through Cloudflare. If your organization restricts outgoing traffic from Atlassian apps, allow gateway.issuemesh.com.
See the list of subprocessors and the privacy policy.
Stopping
- Pause a direction - nothing moves until you resume.
- Revoke a pairing - it ends at once for both spaces; the issues stay as they are.
- Disable a space on the admin page - its pairings pause and keep their settings.
- Uninstall the app - the Hub deletes the site's access tokens and its pairings pause; if the app is not installed again within 90 days, the pairings end.
Reporting a security issue
Write to [security e-mail]. Please include what you found and how to reproduce it.