keelapps

keelapps/Security policy

Security policy

Last updated:

Reporting a vulnerability

Do not open a public issue for a security vulnerability.

Our Atlassian apps handle permission data, content metadata, and scheduled automation inside customer Jira and Confluence sites. A publicly posted vulnerability report is actionable by anyone who reads it before we have shipped a fix.

Report it privately by email to support@keelapps.atlassian.net.

Please include what you found, how to reproduce it, and what an attacker could do with it. If you have a proof of concept, keep it to the minimum needed to demonstrate the issue.

What happens next

Scope

In scope: the keelapps products distributed through the Atlassian Marketplace, and this website.

Out of scope, because they are not ours to fix:

Good faith

We will not pursue legal action against anyone who reports a vulnerability in good faith, stays within the scope above, and gives us reasonable time to fix it before disclosing publicly. We do not currently run a paid bounty programme.

Contact

Security reports: support@keelapps.atlassian.net. Anything else: the support portal.