본문으로 건너뛰기
bobob

In Marketplace review · Updated October 8, 2026

Security

Architecture

  • Built on Atlassian Forge. Code runs on Atlassian's infrastructure; there are no servers of ours.
  • Data is stored in Forge storage in your Atlassian cloud.
  • No egress: the app declares no external domains and makes no calls outside Atlassian. It is eligible for Atlassian's "Runs on Atlassian" program.

Access control

  • The admin page checks on the server, on every call, that the person is a Jira admin.
  • The restricted comment composer posts as the person themselves, so Jira's own permissions apply. It only offers visibilities the issue's project actually has.
  • Adding the app to a project role runs as the admin who clicks the button.

Data handling

  • The app only ever makes comments more private. It never removes a restriction.
  • Comment text is sent back to Jira unchanged when the visibility is set and is never stored or logged.
  • CSV exports neutralise spreadsheet formulas.

Permissions (scopes)

ScopeWhy
storage:appStore rules and the log
read:jira-workRead new comments, projects, issue types and project roles
write:jira-workSet the visibility of new comments; post comments from the composer
read:jira-userRead an author's groups for author-group rules; group names in the editor
manage:jira-projectAdd the app to a project role when an admin clicks "Add the app to this role"

Reporting a vulnerability

Email support@bobob.app with "Security" in the subject. We acknowledge within 72 hours and fix critical issues as a priority.

Questions? Email support@bobob.app. Bobob Apps · bobob.app