Incident Response
SoftComply identifies, assesses, investigates and resolves information security incidents that may affect SoftComply applications, systems or information.
Our response approach supports timely escalation, coordinated investigation, appropriate communication and corrective action. The specific response depends on the nature and severity of the incident, the affected product architecture and the respective responsibilities of SoftComply, Atlassian and other relevant service providers.
Incident-Response Process
SoftComply’s incident-response process covers the following activities:
Detection and reporting – Potential incidents may be identified through security alerts, application or platform logs, customer and employee reports, vulnerability disclosures, service-provider notifications or other monitoring channels.
Assessment and classification – The reported event is assessed to determine whether it constitutes a security incident, the systems and information potentially affected, and its likely severity and impact.
Containment – Appropriate measures are taken to limit further exposure, disruption or unauthorised activity. Depending on the circumstances, these measures may include restricting access, disabling affected functionality, rotating credentials or coordinating containment with a service provider.
Investigation – Relevant information is collected and reviewed to establish the nature, scope, cause and impact of the incident. Investigation records and available evidence are preserved in accordance with applicable procedures.
Remediation and recovery – Identified vulnerabilities, configuration issues or other causes are addressed, and affected services are restored when it is considered safe and appropriate to do so.
Communication – Internal and external stakeholders are informed according to the incident’s severity, applicable contractual commitments and legal requirements.
Post-incident review – Material incidents are reviewed to identify root causes, lessons learned and corrective or preventive actions. Relevant policies, controls, systems or training may be updated based on the findings.
Incident Classification and Escalation
Potential incidents are prioritised according to factors such as:
The type and sensitivity of the information involved
The number and nature of affected customers or users
Evidence of unauthorised access, disclosure, alteration or loss
The effect on application availability, integrity or confidentiality
The likelihood of continued exploitation or harm
The potential legal, contractual or regulatory consequences
Whether the event affects SoftComply-controlled systems, application code or a third-party platform
Higher-severity incidents are escalated to the personnel responsible for coordinating the investigation, response, customer communication and management decisions. External specialists, legal advisers, regulators, law-enforcement authorities or service providers may be involved where appropriate.
Forge and Atlassian Cloud Incidents
Most SoftComply Cloud applications, are built on Atlassian Forge. Atlassian operates the underlying cloud infrastructure, Forge runtime, physical facilities, network controls and platform-level monitoring.
Where an incident originates from or affects Atlassian Cloud or the Forge platform, SoftComply relies on Atlassian to investigate and remediate the underlying platform issue. SoftComply reviews the information available through Atlassian’s operational and security channels, assesses the potential effect on its applications and customers, and takes application-level and communication actions within its responsibility.
SoftComply remains responsible for investigating and addressing incidents involving its application code, requested permissions, dependencies, SoftComply-controlled systems or internal operations.
Current information about the availability of Atlassian Cloud services is available through the Atlassian Statuspage. Information about Atlassian’s security practices is available through the Atlassian Trust Center.
Other Product Architectures
SoftComply Document Manager has a different architecture that includes backend services hosted in Google Cloud. Incidents affecting those services are investigated and managed in coordination with the relevant cloud service provider where necessary.
SoftComply Data Center applications operate within infrastructure controlled by the customer. Customers are responsible for detecting and responding to incidents affecting their networks, servers, operating systems, databases, Atlassian installations, user accounts and configurations.
SoftComply supports the investigation of suspected vulnerabilities or incidents involving the application code it supplies. Customers should preserve relevant logs and diagnostic information and contact SoftComply as soon as reasonably possible.
Personal-Data Breaches
Where an incident involves personal data, SoftComply assesses whether it constitutes a personal-data breach and determines its responsibilities under applicable data-protection law and contractual arrangements.
SoftComply’s role depends on the affected processing activity. Where SoftComply acts as a controller, SoftComply assesses whether notification to a supervisory authority or affected individuals is required. Where SoftComply acts as a processor, SoftComply informs the relevant customer without undue delay after becoming aware of a personal-data breach, in accordance with the applicable Data Processing Agreement.
A notification may initially be based on incomplete information while the investigation continues. Where appropriate, additional information will be provided in phases as it becomes available.
Customer Notifications
SoftComply notifies affected customers where required by applicable law, contract, Data Processing Agreement, or the nature and impact of the incident. The timing and content of a notification depend on the information available, the severity of the incident and the need to avoid compromising containment or investigation activities.
Where relevant and reasonably available, incident communications may include:
A description of the nature of the incident
The affected application, service or information
The known or likely consequences
Containment and remediation actions taken
Recommended actions for affected customers
A contact point for further information
The status of the investigation and expected follow-up
Information required under applicable data-protection law or contractual terms
SoftComply may provide updates as the investigation progresses and a closing communication when the incident has been contained and material findings are available.
Sensitive technical, security or personal information may be withheld where its disclosure could create additional risk, affect another party’s rights or compromise an investigation.
Evidence and Record-Keeping
SoftComply maintains records of material security incidents and the actions taken in response. Depending on the incident, records may include reported facts, assessment decisions, investigation findings, communications, remediation activities and post-incident corrective actions.
Relevant evidence is handled in a manner intended to preserve its integrity and restrict access to authorised personnel. Where specialist forensic investigation is required, SoftComply may engage appropriately qualified external support.
Corrective Actions
Following a material incident, SoftComply evaluates whether additional corrective or preventive actions are required. These may include:
Application or configuration changes
Credential or access-control changes
Dependency updates or security patches
Additional monitoring or alerting
Updates to policies, procedures or technical controls
Personnel training or awareness activities
Supplier or service-provider follow-up
Updates to risk assessments or business-continuity arrangements
Corrective actions are assigned and tracked according to their priority and the risk they are intended to address.
Reporting a Security Incident or Vulnerability
Suspected security incidents and vulnerabilities involving a SoftComply application may be reported through:
Email: support@softcomply.com
Support portal: SoftComply Support Portal
SoftComply’s business hours are 10:00–16:00 CET, Monday to Friday, excluding Estonian national holidays. In accordance with SoftComply’s current Service Level Agreement, support requests receive a response within no more than 24 business hours from the time of submission.
Where a report concerns a suspected security incident or vulnerability, customers should clearly identify this in the subject line or ticket description so that the request can be assessed and escalated appropriately.
The 24-business-hour support response target does not replace any shorter notification or response obligation that may apply under an applicable contract, Data Processing Agreement or law.
An initial report should include, where available:
The affected SoftComply application and hosting model
The affected Jira or Confluence site, without including unnecessary personal data
A description of the observed activity
The date and time the issue was identified
Steps for reproducing the issue, if applicable
Relevant screenshots, error messages or log references
Contact information for coordinating the investigation
Do not include passwords, access tokens, private keys or unnecessary personal data in the initial report. SoftComply may provide or agree an appropriate method for exchanging sensitive supporting material.
Responsible Security Testing
Customers and security researchers must obtain prior written authorisation before conducting penetration testing or other active security testing against SoftComply applications or related services.
Testing must not disrupt services, access another customer’s information, compromise user privacy or breach Atlassian’s applicable terms and security-testing requirements.
Potential vulnerabilities should be reported privately and should not be publicly disclosed before SoftComply and the relevant platform provider have had a reasonable opportunity to investigate and address the issue.
Review and Testing
SoftComply reviews its incident-response arrangements periodically and following material incidents or significant changes to its products, services or risk environment. Incident-response and business-continuity procedures may be exercised through tabletop scenarios or other appropriate testing activities.
Lessons identified through incidents, exercises, security assessments and service-provider notifications are considered as part of the continual improvement of SoftComply’s security programme.
Incident-Response Contact
For security incidents, suspected vulnerabilities or questions about SoftComply’s incident-response process, contact support@softcomply.com or use the SoftComply Support Portal.
For privacy-related incidents or personal-data-breach questions, contact privacy@softcomply.com.
Last updated: July 2026