In Marketplace review · Updated October 8, 2026
Security
Architecture
- Built on Atlassian Forge. Code runs on Atlassian's infrastructure; there are no servers of ours.
- Data is stored in Forge storage in your Atlassian cloud.
- No egress: the app declares no external domains and makes no calls outside Atlassian. It is eligible for Atlassian's "Runs on Atlassian" program.
Access control
- Every management action is checked on the server: Jira admin, or membership of a notice editor group chosen by a Jira admin. Settings and channels are for Jira admins only.
- Viewers can only record a view or close for a notice that is showing and meant for them.
- A viewer's groups are used only to decide what to show and are never sent to the browser.
Data handling
- Notice text is rendered as plain text with a small safe formatting set (bold, links, line breaks). No HTML or scripts from notice content ever run. Links must be http(s), mailto or a path on your own site.
- Errors shown to people never include internal details.
Permissions (scopes)
| Scope | Why |
|---|---|
| storage:app | Store notices, settings and who saw or closed them |
| read:jira-user | Read a viewer's groups for group audiences, and group names in the editor |
| read:jira-work | Check that the person managing notices is a Jira admin |
Reporting a vulnerability
Email support@bobob.app with "Security" in the subject. We acknowledge within 72 hours and fix critical issues as a priority.
Questions? Email support@bobob.app. Bobob Apps · bobob.app