Security Policy

Last Updated: March 24, 2026  •  Publisher: PPLX Software

1. Overview

TeamOps is a Forge-native Jira application for onboarding, offboarding, and leave management that runs entirely on Atlassian's infrastructure. It carries the "Runs on Atlassian" trust badge, meaning there are no external servers, no third-party hosting, and no data leaving Atlassian's platform.

Key facts:

  • Zero external servers or databases
  • Zero external network calls or data egress
  • PPLX Software has no access to your data
  • All data stays on Atlassian's infrastructure, in your data residency region

2. Data Storage & Residency

All TeamOps data is stored in the Forge Custom Entity Store, a managed storage service provided by Atlassian as part of the Forge platform.

3. Access Controls

PPLX Software Has No Access to Customer Data

The Forge platform runs app code inside an isolated sandbox. PPLX Software, as the app publisher, cannot access, view, or retrieve any data stored by TeamOps on your Atlassian site. There is no admin backdoor, no remote access, and no telemetry that transmits customer data.

Role-Based Access Within Your Organization

TeamOps enforces role-based access control (RBAC) with three roles, checked on every server-side API call:

RoleAssignmentData Access
HR AdminJira group membershipFull access to all employee data, configuration, data export, and erasure
ManagerJira group membershipTeam members' leave requests, onboarding, and offboarding progress only
EmployeeDefault for all authenticated usersOwn leave requests, onboarding, and offboarding tasks only

Authentication

TeamOps relies entirely on Atlassian OAuth 2.0 for authentication. The app does not collect credentials, manage sessions, or implement its own login flow. Users are authenticated by Atlassian before any app code executes.

4. Platform Security

TeamOps runs on Atlassian's Forge platform, which provides enterprise-grade security infrastructure:

Certification / StandardHolderCoverage
SOC 2 Type IIAtlassianInfrastructure, compute environment, and data storage used by Forge apps
ISO 27001AtlassianInformation security management across Atlassian's platform
AES-256 EncryptionAtlassianAll data at rest in the Forge Custom Entity Store
TLS 1.2+AtlassianAll data in transit within the Forge platform

PPLX Software does not hold independent SOC 2 or ISO 27001 certification. Because TeamOps is Forge-native with no external infrastructure, Atlassian's platform certifications cover the entire runtime and storage environment that the app uses.

For details on Atlassian's security posture, see the Atlassian Trust Center.

5. Data Processing

What Data Is Collected

TeamOps collects only the data necessary for leave management, employee onboarding, and offboarding:

How Data Is Used

GDPR Compliance

TeamOps includes built-in GDPR features: data export (right of access / portability) and data erasure (right to be forgotten), both available to HR Admins directly within the app.

For full details, see our Privacy Policy.

6. Incident Response

PPLX Software follows a structured incident response process:

  1. Detection & Triage — Potential security issues are assessed for severity and scope within 24 hours of identification.
  2. Containment — For critical vulnerabilities, a patched version is submitted to the Atlassian Marketplace as an expedited update.
  3. Notification — Affected customers are notified through the Marketplace listing and direct communication for critical issues.
  4. Remediation — Root cause analysis is performed and preventive measures are implemented.
  5. Disclosure — Material security issues are disclosed responsibly with appropriate timelines.

7. Vulnerability Reporting

If you discover a security vulnerability in TeamOps, please report it to us so we can address it promptly.

Contact: support@pplxsoftware.com

Please include a description of the vulnerability, steps to reproduce, and any relevant screenshots or logs. We aim to acknowledge reports within 48 hours and provide a resolution timeline within 5 business days.

8. App Architecture

TeamOps is built on Atlassian Forge, a serverless app platform where all code runs inside Atlassian's infrastructure. This architecture provides inherent security advantages over traditional Atlassian Connect apps:

PropertyTeamOps (Forge)Connect Apps (Traditional)
Code executionAtlassian's serversPublisher's external servers
Data storageAtlassian's infrastructurePublisher's external databases
Network callsNone (zero external fetch)Typically many external calls
Data egressNoneData may leave Atlassian
Publisher data accessNone (sandbox isolation)Full access to hosted data

Additional Security Measures

Questions?

For security-related questions or concerns, contact us at support@pplxsoftware.com.

For information about Atlassian's platform security, visit the Atlassian Trust Center.