Security — Support Attachment Sync for Jira

Last updated: 21 September 2026 (first publication of this page; it describes version 6, the version on sale today).

This page describes how the App handles and protects data, how we manage vulnerabilities, and what security certifications we hold. It is separate from the Privacy Policy, which lists what is stored; and from the Data Processing Agreement, which sets out the terms we process personal data under. Where the three overlap, the Privacy Policy is the authoritative list. It describes the version of the App that is on sale today.

1. Where the App runs

The App runs entirely on Atlassian Forge, inside Atlassian's infrastructure. There is no server of ours: no database, no file store, no queue outside Forge. Everything the App keeps is held in Forge storage, scoped to the installing Jira site, and Atlassian's own security controls apply to it; the transfers themselves wait in a Forge queue declared in the App's manifest. Diagnostic logs are written through the Forge logging platform and are described in section 2.

2. Data handling

3. Encryption and transport

4. Access control

5. Vulnerability management

6. Certifications

None. IDEAL WORKS does not hold SOC 2 or ISO 27001 certification, the App is not Cloud Fortified, and there is no independent audit report. We would rather you decide with that in front of you than discover it later.

7. Contact

support@conduitworks.dev

8. Trademarks

The Intercom name and logos are the trademarks or service marks of Intercom, Inc. or its affiliates in the U.S. and other countries. Atlassian, Jira and Forge are trademarks of Atlassian Pty Ltd. IDEAL WORKS is an independent vendor and is not affiliated with, endorsed by, or sponsored by Intercom, Inc. or Atlassian Pty Ltd. These names are used only to describe what this App interoperates with.