ScriptRunner for Jira
OVERALL RATINGS
INSTALLS
35,019
SUPPORT
- Partner Supported
- Cloud Migration Assistance
TRUST SIGNALS
Privacy and Security details
The Atlassian Marketplace partner is responsible for the accuracy of the information provided below. Details with a verified status are confirmed by Atlassian. For any further queries, contact the partner.
Data storage and management
End-User Data processed and/or stored outside of Atlassian apps and services (excluding process/storage of End-User Data in logs)
The app processes and stores the following types of End-User Data:
Email address
IP address
Public name
Content posted, received or shared in the app by end-users
Content logged by the Jira Admin in their scripts
Data residency for in-scope End-User Data
Marketplace app supports data residency and stores End-User Data independently outside of Atlassian apps and services in the following locations:
🇺🇲
United States of America
🇩🇪
Germany
More information on the Marketplace app’s data residency policy can be found in app’s product documentation or please contact the respective Marketplace app partner at
security@adaptavist.comApp REST APIs
This app does not provide REST APIs.
List of in-scope End-User Data
App stores the following types of in-scope end-user data:
Email address
IP address
Public name
Content posted, received or shared in the app by end-users
Content logged by the Jira Admin in their scripts
List of out-of-scope End-User Data
App stores the following types of out-of-scope end-user data:
App analytics events (performance, UX metrics)
User analytics and general app usage telemetry
Migration of in-scope End-User Data between data residency supported locations
Yes
End-User Data shared with third-party entities
End-User Data accessed in logs
Yes
End-User Data processed and/or stored in logs outside of Atlassian apps and services
Yes
End-User Data in logs shared with third-party entities
No
End-User Data in logs shared with third party entities integral for app functionality
No
End-User Data stored after app is uninstalled
Minimum storage period post un-install:
89 days
Maximum storage period post un-install:
90 days
Custom retention period for End-User Data
No
Supports customer-managed egress
No.
The app only accesses domains declared during installation.
Security and compliance
Contact for app security issues
App’s e-mail contact:
security@adaptavist.comIntegration permissions with Atlassian apps
Access content using the permissions of the user running the app.
Administer the Jira site.
Delete board configuration settings, features, and properties.
Delete content in Jira.
Delete sprints and their properties.
Take Jira administration actions (e.g. create projects and custom fields, view workflows, manage issue link types).
Create and edit project settings and create new project-level objects (e.g. versions and components).
Fetch, register, refresh, and delete dynamically declared Jira webhooks.
Create, manage and delete customers and organizations. Add and remove customers and organizations from service desks.
Administer a project in Jira.
Access and interact with your data from outside of Atlassian.
Access and interact with your data as the logged-in user from outside of Atlassian.
View the configuration, project features, filters, properties, and quick filters for a board.
View boards, issues on a board, issues from a backlog, reports, and versions.
View builds.
View, browse, and read information from Jira.
View deployments.
View and search for epics, and issues related to an epic.
View feature flags.
View issue details.
View issues, issue estimations, and the field used for estimations.
View user information in Jira that the user has access to, including usernames, email addresses, and avatars.
Read Jira project and issue data, search for issues, and objects associated with issues like attachments and worklogs.
View JQL.
View projects.
View remote links.
Search and view request types.
Read customer request data, including approvals, attachments, comments, request participants, and status/transitions. Read service desk and request types, including searching for request types and reading request type fields, properties and groups.
View repositories and check if data exists for the supplied properties.
View sprints and sprint related issues and properties.
Read and write to app storage service
create, modify and delete app properties data
Create and update the configuration and project for a board. View and update features, filters, properties, and quick filters for a board.
Move issues to a backlog and from a backlog to a board.
Create, update, and delete builds.
Create or edit content in Jira, but not delete content.
Create, update, and delete deployments.
Remove issues from epic, move issues to epic, rank epics, and partially update epics.
Create, update, and delete feature flags.
Move (rank) issues and update issue estimates.
Create and edit issues in Jira, post comments as the user, create worklogs, and delete issues.
Create, update and delete links.
Create and edit customer requests, including add comments and attachments, approve, share (add request participants), subscribe, and transition.
Create, update, and delete development information, delete repository and development information entities.
Update sprints, move issues to sprints, and update the order of sprints.
More information on the justification of app’s integration permissions are shared by the app’s partner hereCompliance certifications
SOC2
ISO27001
Marketplace Security Bug Bounty Program participant
Yes.
App is a participant in Marketplace Security Bug Bounty Program.
CAIQ Lite
Yes,
CAIQ Lite responseSecurity policy
Full disk encryption for data stored outside of Atlassian
Yes
App accesses Atlassian Personal Access Tokens (PATs), user account passwords, or another type of shared secret
No
Privacy
Privacy policy
Atlassian's privacy policy is not applicable to the use of this app. Please refer to the privacy policy provided by this app's partner.
Partner privacy policyCompany/Organization is a 'data controller' under the General Data Protection Regulation (GDPR) with reference to this app
No
Company/Organization is a 'data processor' under the General Data Protection Regulation (GDPR) with reference to this app
Yes.
Company/Organization is a 'data processor' for the following types of End-User Data:
Email address
IP address
Public name
Content posted, received or shared in the app by end-users
Company/Organization is a 'business' under the California Consumer Privacy Act of 2018 (CCPA) with reference to this app
No
Company/Organization is a 'service provider' under the California Consumer Privacy Act of 2018 (CCPA) with reference to this app
Yes.
Company/Organization is a 'service provider' for the following types of End-User Data:
Email address
IP address
Public name
Content posted, received or shared in the app by end-users
General Data Protection Regulation (GDPR) approved mechanism for transferring European Economic Area (EEA) residents’s End-User Data outside of the EEA
No. App does not transfer EEA residents' data outside of the EEA.
Privacy enhancing technologies (PETs) used to protect End-User Data
No
Data Processing Agreement (DPA) for customers
Yes,
DPA
Atlassian trust programs
CLOUD FORTIFIED
This app offers additional security, reliability, and support through:
Marketplace Bug Bounty participation
Timely reliability checks
24hr support response time
How do these programs address app trust?
Marketplace programs help Marketplace partners achieve the highest consistent standards for application security and privacy.
About trust programsDid you find this information useful?
Atlassian will use this feedback to serve you better.