1. Report a vulnerability
Send security reports to info@ulte.net with "Security" in the subject. We confirm receipt within two business days. Please give us reasonable time to fix an issue before disclosing it. Vulnerabilities in apps sold on the Atlassian Marketplace are fixed within the timelines of the Atlassian Marketplace security bug fix policy.
2. Scope and owner
Ulte is the software studio of Event Space Sp. z o.o., Olsztyn, Poland. Security is owned by the company's managing developer, who is the security contact for every product and approves every change to production.
3. Access and accounts
- Two-step verification is enabled on every company account that supports it, including Atlassian, Google Workspace, Stripe, domain and hosting accounts.
- Servers are accessed with SSH keys.
- Passwords are unique, long and kept in a password manager.
- Access is granted only to people who need it, and all access to company systems is reviewed every quarter.
- API tokens and secrets are kept out of source code, have an expiry date where the provider supports it, are rotated at least once a year and at once when exposure is suspected.
4. Devices
Work devices use full disk encryption, endpoint protection and automatic security updates. Operating systems and software that no longer receive security updates are not used.
5. Development
- Code is written with the OWASP Top 10 in mind: input validation, output escaping, least privilege and no secrets in code or logs.
- Apps for Jira request only the scopes they need and run on Atlassian Forge without a vendor-hosted backend.
- Dependencies are checked with npm audit or the equivalent tool before each release and updated with the platform SDKs.
- Each release is tested on a development environment with real platform events before it is deployed to production.
6. Data protection
Customer data is processed only to provide the product and is described per product in the privacy policy. Connections use TLS. Secrets are stored encrypted (Forge secret storage for apps for Jira, encrypted database fields for Ulte Mail Sync). Personal data is never written to logs.
7. Logging
Application errors and deliveries are logged with timestamps and without personal data or secrets. Access to logs is limited to the security owner. Retention is set per product in the privacy policy.
8. Incident response plan
- Detect and record. Any suspected incident, from a report, an alert or a platform notice, is recorded with the time and what is known.
- Contain. Affected credentials are revoked and rotated, affected functions are disabled or the app version is rolled back.
- Assess. We establish which customers, data and products are affected.
- Notify. Affected customers and Atlassian (for Marketplace apps) are informed without undue delay and within 72 hours of confirmation, following Atlassian's incident and vulnerability notification templates. Where personal data is involved, customers receive what they need for their own GDPR notifications.
- Fix and recover. The cause is fixed, the fix is deployed and the service is checked end to end.
- Learn. A short written review records the cause and the changes made to prevent a repeat.
9. Review
This policy is reviewed at least once a year and after every incident. The date at the top shows the latest version.