Security

Table of Contents

Security is integrated into the design, development and operation of SoftComply applications. We apply technical and organisational controls appropriate to each product’s architecture, the information it processes and its deployment model.

SoftComply develops applications for Atlassian Cloud and Data Center. Most SoftComply Cloud applications are built on Atlassian Forge, like the SoftComply Risk Manager Plus and others, and benefit from the security controls of the Atlassian Cloud platform. SoftComply Document Manager is also built on Atlassian Forge but it includes backend services hosted in Google Cloud. Data Center applications run within infrastructure operated and secured by the customer.

This page provides an overview of our security approach. Product-specific information is available through the Privacy & Security section of the applicable Atlassian Marketplace listing and supporting product documentation.

Security Governance

SoftComply maintains an information security management programme designed with reference to ISO/IEC 27001. It includes policies and procedures covering areas such as risk management, access control, secure development, vulnerability management, incident response, business continuity, data protection and supplier management.

Security responsibilities are assigned within the organisation, and personnel are required to follow applicable information security policies. Security risks and controls are reviewed as part of SoftComply’s ongoing management and product-development activities.

SoftComply is working towards ISO/IEC 27001 certification, with the first-stage certification audit currently planned for 2027.


Cloud Architecture and Shared Responsibility

Forge-based Cloud applications

Most SoftComply Cloud applications are built on Atlassian Forge. Forge applications run within Atlassian’s cloud environment rather than SoftComply’s corporate network. Atlassian operates the underlying cloud infrastructure, Forge runtime, physical security, network security and platform-level availability controls.

Forge provides logical tenant isolation, controlled application permissions and platform-managed authentication. Customer application data processed through Forge remains within Atlassian’s infrastructure unless a product’s published data-handling information expressly identifies an external service or data flow.

SoftComply remains responsible for the security of its application code, requested permissions, application configuration, third-party dependencies and secure development practices. This allocation of responsibilities follows Atlassian’s shared-responsibility model.

Forge-based applications request only the Atlassian scopes required to provide their documented functionality. Customers can review the permissions requested by an application before approving its installation.

Further information: Security for Forge apps

SoftComply Document Manager

SoftComply Document Manager has a different architecture that includes backend services hosted in Google Cloud. Security controls for these services include access restrictions, encryption and cloud-platform security capabilities appropriate to the services used. 

Data Center applications

SoftComply Data Center applications are installed within the customer’s Atlassian Data Center environment. The customer is responsible for securing and operating the underlying infrastructure, network, operating systems, database, Atlassian installation, backups and identity-management configuration. SoftComply is responsible for the security of the application code it supplies and for addressing identified product vulnerabilities.


Authentication and Access Control

Forge-based SoftComply applications rely on Atlassian Cloud for user authentication and session management. SoftComply does not independently collect or store customers’ Atlassian passwords. Authentication controls such as single sign-on, multi-factor authentication and user-lifecycle management are configured and managed through the customer’s Atlassian organisation and identity provider.

Application access is governed by the permissions configured in Jira or Confluence, together with any product-specific roles or restrictions provided by the SoftComply application.

Access to SoftComply-controlled business and development systems is restricted according to business need. Privileged access is limited to authorised personnel and protected through appropriate authentication controls. Access rights are reviewed and updated when roles or responsibilities change and are removed when no longer required.

SoftComply personnel do not routinely access customer content held within Forge-hosted application storage. If customer information is voluntarily supplied through a support request, access is restricted to personnel who need it to investigate or resolve the request.


Data Protection and Encryption

Data transmitted between users, Atlassian Cloud and Forge-based applications is protected using HTTPS and supported TLS protocols. Encryption of Forge-hosted data at rest and the associated infrastructure-level key management are provided by Atlassian.

For product services operated outside Atlassian Forge, SoftComply uses the encryption and security capabilities of the applicable cloud provider. Access to these environments, services and credentials is restricted according to business need.

Customers control access to their Jira and Confluence content through Atlassian permissions and administrative settings. Where supported by the product and configuration, customers may also use Atlassian data-residency controls to select an available location for in-scope data.

Further information about data residency, retention, international transfers and SoftComply’s role under data-protection law is available on the Data Protection & Privacy page.

Further information: Atlassian Security Measures


Secure Software Development

SoftComply applies security practices throughout the software development lifecycle. These practices include security consideration during design, peer review of code changes, controlled source-code access, dependency management, automated testing and security checks appropriate to the application and release.

Development and production responsibilities are separated where appropriate. Changes are tested and reviewed before release, and deployments are performed through controlled processes. Source-code repositories and development systems are restricted to authorised personnel.

Application permissions and external data flows are reviewed when new functionality is introduced. Forge-based applications are designed to use the minimum Atlassian scopes and external connections reasonably required for their documented functionality.

Third-party and open-source dependencies are monitored and updated according to the risk presented by identified vulnerabilities, product compatibility and the availability of an appropriate fix.


Vulnerability Management

SoftComply maintains processes for identifying, assessing, prioritising and remediating security vulnerabilities. Potential vulnerabilities may be identified through automated security checks, dependency monitoring, Atlassian Marketplace security notifications, internal testing, customer reports or reports from independent security researchers.

Findings are evaluated according to factors such as severity, exploitability, affected functionality, information exposure and customer impact. Remediation is prioritised according to the assessed risk and applicable Atlassian Marketplace requirements.

SoftComply participates in applicable Atlassian Marketplace security programmes. Most SoftComply apps hold Atlassian Cloud Fortified status and SoftComply participates in the Marketplace Security Bug Bounty Program, through which independent security researchers can report potential vulnerabilities. Current programme participation should be verified through the application’s Atlassian Marketplace listing.

Atlassian is responsible for vulnerability management and security testing of the underlying Atlassian Cloud and Forge infrastructure. SoftComply is responsible for vulnerabilities in its application code and dependencies.

Security researchers and customers may report a suspected vulnerability to security@softcomply.com. Please do not include passwords, access tokens or unnecessary personal data in the initial report.

Further information:


Monitoring and Security Logging

SoftComply uses application, development and business-system logging appropriate to each system’s purpose and architecture. Security-relevant events and alerts are assessed and escalated in accordance with applicable internal procedures.

For Forge-based applications, platform-level infrastructure monitoring, network monitoring and operational logging are managed by Atlassian. SoftComply monitors information available to it through application-level logs, security notifications, customer reports and Atlassian’s developer and Marketplace security channels.

Logging is designed to support troubleshooting, security investigation and operational oversight while limiting unnecessary exposure of sensitive information. Access to SoftComply-controlled logs is restricted according to business need and applicable retention requirements.


Incident Response

SoftComply evaluates suspected incidents according to their severity and potential impact on customers, information and service availability.

Where an incident affects Atlassian Cloud or the Forge platform, SoftComply works with and relies on Atlassian for the investigation and remediation of the underlying platform issue. SoftComply remains responsible for investigating and addressing incidents involving its application code or SoftComply-controlled systems.

Affected customers are notified where required by applicable law, contract or the nature and impact of the incident. Further information is available on the Incident Response page.


Business Continuity and Availability

SoftComply maintains business continuity and recovery procedures intended to support its critical business activities during a disruption. These procedures address areas such as business-impact assessment, responsibilities, communications, recovery actions and periodic review or testing.

For Forge-based Cloud applications, availability, infrastructure resilience, backups and disaster recovery of the underlying platform are managed by Atlassian. SoftComply therefore relies on Atlassian’s cloud architecture, operational controls and applicable service commitments for platform-level continuity.

SoftComply is responsible for maintaining its application code, supporting customers, coordinating application-level recovery actions and communicating relevant information where a disruption affects a SoftComply application.

For Data Center applications, customers are responsible for the availability, backup and recovery of their own Atlassian environment and application data.

Further information: Atlassian Trust Center


Employee and Endpoint Security

SoftComply personnel are required to comply with applicable information security and confidentiality obligations. Security awareness is addressed through onboarding and ongoing internal practices appropriate to personnel responsibilities.

SoftComply-managed endpoints are protected through measures such as access controls, device encryption, malware protection, software updates and remote-management capabilities, as applicable. Access to company systems is restricted to authorised users and removed when employment or the relevant business need ends.

Personnel access to customer information is limited according to role and business need. SoftComply personnel do not access customer application content stored within Forge-hosted applications unless the customers request it and grant the access.


Security Assurance and Documentation

SoftComply supports customer security and procurement assessments by providing available product-security information, architecture documentation, completed security questionnaires and relevant policy summaries. Certain confidential information may be provided only under an appropriate non-disclosure agreement.

Atlassian’s certifications and assurance reports apply to Atlassian’s infrastructure and cloud services; they should not be interpreted as certifications independently held by SoftComply. SoftComply’s current security status and applicable Marketplace programme participation are described on the Compliance page.

For security questions, vendor assessments or vulnerability reports, contact security@softcomply.com.