본문으로 건너뛰기
bobob

In Marketplace review · Updated October 7, 2026

Security

Architecture

  • Built on Atlassian Forge. Code runs on Atlassian's infrastructure; there are no servers of ours.
  • Data is stored in Forge storage in your Atlassian cloud.
  • No egress: the app declares no external domains and makes no calls outside Atlassian. It is eligible for Atlassian's "Runs on Atlassian" program.

Access control

  • Every management action is checked on the server against Jira permissions: help-center-wide notices require Jira admin; portal notices require admin of that service project. Showing or hiding a settings page is never treated as permission.
  • Project admins can only see and change notices of their own portal.
  • Customers can only record a close for a notice that is showing and is meant for them. Notices that can't be closed refuse it.
  • A customer's organizations are used only to decide what to show and are never sent to the browser.

Data handling

  • Notice messages are rendered as text with a small, safe formatting set (bold, links, line breaks). No HTML or scripts from notice content ever run. Links must be http(s), mailto or a path on your own site.
  • Errors shown to admins never include internal details; details go only to the app's Forge logs.

Permissions (scopes)

All Jira Service Management permissions are read-only.

ScopeWhy
storage:appStore notices and who closed them
read:jira-user, read:jira-workCheck that the person managing notices is a Jira or project admin
read:servicedesk:jira-service-managementList portals and match a project to its portal
read:requesttype:jira-service-managementRequest type targeting
read:organization:jira-service-managementCustomer organization targeting

Reporting a vulnerability

Email support@bobob.app with "Security" in the subject. We acknowledge within 72 hours and fix critical issues as a priority.

Questions? Email support@bobob.app. Bobob Apps · bobob.app