Partner Security Policy

Effective date: April 30, 2026

This Partner Security Policy describes the security practices for OKR Tracker for Jira (the “App”), provided by Individual Entrepreneur Ihor Oleksandrovych Vasylenko, a sole proprietor registered in Ukraine (“Vendor”, “we”, “us”, or “our”).

For security questions or to report a potential security issue, contact: support@florenco.tech.

1. Scope

This Policy applies to the operation of the App in Atlassian Jira Cloud using the Atlassian Forge platform.

It describes our security approach for:

2. Hosting Model and No External Servers

The App is built on Atlassian Forge and uses Atlassian-hosted Forge infrastructure, including Forge SQL.

At the time of this Policy:

This means the App’s runtime and storage model is designed to avoid unnecessary external data transfers and to minimize the number of systems involved in processing customer data.

3. Data Access Model

The App processes data only as needed to provide OKR functionality inside Jira Cloud.

Examples include:

Access to App functionality is limited by:

4. Security Controls

We apply reasonable technical and organizational controls appropriate for the App’s size, architecture, and hosting model.

Current security controls include:

No security measure is absolute, but we aim to apply controls proportionate to the App’s design and risk profile.

5. Vulnerability Management

We take a reasonable and practical approach to identifying, assessing, and addressing vulnerabilities affecting the App.

Our vulnerability management practices include:

If a vulnerability is confirmed, we aim to remediate it within a timeframe appropriate to its severity and operational impact. Critical issues are prioritized ahead of normal feature work.

Security reports can be sent to: support@florenco.tech

We ask that reporters provide enough detail to help us reproduce and assess the issue.

6. Incident Response

If we become aware of a security incident affecting the App, we aim to respond in a structured and reasonable manner.

Our incident response approach generally includes:

For incidents involving Atlassian-hosted platform services, our response may depend in part on Atlassian platform visibility, controls, and notifications available to Forge partners.

7. Logging, Monitoring, and Troubleshooting

The App may use logging and operational diagnostics available through the Atlassian Forge platform to troubleshoot errors, investigate operational issues, and support security review.

We aim to use such information only as necessary for:

8. Data Sharing and Third Parties

The App depends on:

Other than the Atlassian-hosted services required to operate the App, the current implementation does not intentionally transmit customer App data to vendor-operated external servers for separate processing.

We do not sell customer data.

9. Customer Responsibilities

Customers are responsible for their Jira configuration, user administration, and internal decisions about which users are granted access to Jira, the App, and related project content.

Customers should also review Atlassian’s own security and compliance materials for the underlying Jira Cloud and Forge platform environment.

10. Policy Updates

We may update this Partner Security Policy from time to time to reflect changes in the App, our practices, or review requirements.

The updated version becomes effective when published on this page.

11. Contact

Individual Entrepreneur Ihor Oleksandrovych Vasylenko
Ukraine
Email: support@florenco.tech