Security

Security and permissions, without the marketing fog.

Resultary is a Jira Cloud Forge app. This page describes the current app architecture and requested permissions so administrators can evaluate it before installation.

Forge-hosted architecture

Core app execution and persistent application state use Atlassian Forge. Resultary does not operate a separate custom backend database for its core monitor state.

Requested Jira / Forge scopes

ScopeWhy Resultary uses it
storage:appStore monitor configuration, incident state, audit/operational state and related app data in Forge-hosted storage.
read:jira-workRead the Jira evidence required to verify configured business outcomes.
write:jira-workCreate and update Resultary Jira incident records and perform the Jira writes required by configured incident handling.
report:personal-dataReport stored Jira account identifiers through Atlassian Forge privacy mechanisms so closed or updated account references can be handled.

Credentials and secrets

Protected heartbeat credentials and supported notification webhook URLs use Forge secret storage. Resultary does not require your Atlassian account password or a Jira Personal Access Token for normal Forge operation.

External network destinations

The app manifest currently permits backend egress only to supported Slack incoming webhooks and Microsoft Power Platform / Teams webhook endpoints. Those destinations are used only when an administrator configures the corresponding notification integration.

Data residency

Persistent Forge-hosted storage inherits Atlassian Forge data-residency capabilities. Hosted data can follow the customer’s supported Atlassian data-residency location. Optional Slack or Teams notifications are external egress and are governed by the administrator’s chosen service and configuration.

Atlassian Forge data residency documentation ↗

Tenant separation

Forge-hosted storage is partitioned by app installation and Atlassian site. Resultary does not intentionally use a shared custom database for customer monitor state.

No Jira Automation rule editing

Resultary observes protected run signals and configured Jira outcomes. It does not edit, enable, disable or delete Jira Automation rules.

Vulnerability reporting

Report a suspected security issue to support@getresultary.com with “Resultary Security” in the subject. Do not include passwords, tokens, heartbeat credentials or webhook secrets in ordinary email.

Security status during private beta

Resultary is in private beta and has not claimed certifications it does not hold. Security and Marketplace disclosures will be updated as the product progresses toward general commercial availability.