In Marketplace review · Updated October 8, 2026
Security
Architecture
- Built on Atlassian Forge. Code runs on Atlassian's infrastructure; there are no servers of ours.
- Data is stored in Forge storage in your Atlassian cloud.
- No egress: the app declares no external domains and makes no calls outside Atlassian. It is eligible for Atlassian's "Runs on Atlassian" program.
Access control
- The admin page checks on the server, on every call, that the person is a Jira admin.
- The restricted comment composer posts as the person themselves, so Jira's own permissions apply. It only offers visibilities the issue's project actually has.
- Adding the app to a project role runs as the admin who clicks the button.
Data handling
- The app only ever makes comments more private. It never removes a restriction.
- Comment text is sent back to Jira unchanged when the visibility is set and is never stored or logged.
- CSV exports neutralise spreadsheet formulas.
Permissions (scopes)
| Scope | Why |
|---|---|
| storage:app | Store rules and the log |
| read:jira-work | Read new comments, projects, issue types and project roles |
| write:jira-work | Set the visibility of new comments; post comments from the composer |
| read:jira-user | Read an author's groups for author-group rules; group names in the editor |
| manage:jira-project | Add the app to a project role when an admin clicks "Add the app to this role" |
Reporting a vulnerability
Email support@bobob.app with "Security" in the subject. We acknowledge within 72 hours and fix critical issues as a priority.
Questions? Email support@bobob.app. Bobob Apps · bobob.app