Security

Security Policy

Last updated: 30 August 2026. Contact: info@berkly.nl

I am Berk Karabacak, an individual developer. I publish Atlassian Forge apps for Jira Cloud under the Berkly name. This page is the security policy for those apps.

Each app runs on Atlassian Forge. Intended design is no egress. App data stays in the customer Jira Cloud site and in Atlassian-hosted Forge storage. I do not store customer Jira data on my own servers.

1. Platform

Each app runs on Atlassian Forge. Intended design is no egress. App data stays in the customer Jira Cloud site and in Atlassian-hosted Forge storage. I do not store customer Jira data on my own servers.

2. Access

Apps use only the Forge scopes shown on the install screen. I do not hold customer passwords, API tokens, or copies of Jira issue data.

3. Dependencies

Production npm dependencies are scanned in CI with npm audit --omit=dev --audit-level=high. Dependabot is enabled. High and critical issues are fixed before a Marketplace version is submitted.

4. Reports

Report security issues to info@berkly.nl.

5. Privacy / DPA

https://berkly.nl/privacy and https://berkly.nl/dpa

6. Changes

Material changes get a new date at the top.