Security at MayaTech Solutions


Built for Responsible Jira Data Handling

Scrumpacity is designed to help teams plan, track, and learn from their sprints without introducing unnecessary systems or data transfers.

The app is built on Atlassian Forge and operates through declared permissions within the Atlassian Cloud environment. Scrumpacity does not require your Jira password or API token, and customer data is not sent to generative AI services.

  • Information Scrumpacity stores

    Scrumpacity may store app-specific information such as:

    • App and project configuration

    • Team capacity profiles and availability adjustments

    • Sprint baselines captured when a sprint begins

    • Completed sprint outcomes and trend history

    • User-specific settings and preferences

    • Atlassian account identifiers needed to associate saved settings with users

    • Technical records required to operate, troubleshoot, and maintain the app

    Scrumpacity does not require customers to provide Atlassian passwords, personal API tokens, payment-card information, government identification numbers, or medical information.

    Customers should not intentionally enter highly sensitive personal information into Scrumpacity.

  • Authentication and authorization

    Scrumpacity relies on Atlassian for user authentication. MayaTech Solutions does not create or manage separate Scrumpacity passwords.

    Access to Scrumpacity begins with access to the customer’s Atlassian site. Administrative and configuration functions are additionally limited through Jira permissions and app-level authorization checks.

    Only authorized Jira administrators can install the app or approve changes to its requested permissions.

  • Data location and infrastructure

    Scrumpacity is built using Atlassian Forge. App functions communicate with Jira through authenticated Atlassian APIs, and app-managed information is stored using Forge-hosted services.

    Atlassian is responsible for securing the underlying Forge and Atlassian Cloud infrastructure. MayaTech Solutions is responsible for Scrumpacity’s application code, requested permissions, configuration, and secure development practices.

    Customers remain responsible for:

    • Managing Jira users, groups, and project permissions

    • Reviewing requested app permissions before installation

    • Removing access when it is no longer required

    • Determining what information is appropriate to place in Jira

    • Maintaining their organization’s endpoint, identity, and account security

  • Secure development practices

    Secure development practices

    MayaTech Solutions applies security-focused practices throughout Scrumpacity’s development and maintenance, including:

    • Reviewing application permissions and limiting them to required functions

    • Separating development, staging, and production environments

    • Testing changes before production deployment

    • Avoiding hard-coded credentials and secrets

    • Reviewing third-party dependencies

    • Limiting sensitive information in application logs

    • Maintaining privacy-reporting and account-erasure workflows required for stored personal data

    • Triaging reported vulnerabilities according to their potential impact

    Security controls and processes will continue to evolve as Scrumpacity and MayaTech Solutions mature.

  • Vulnerability and incident response

    Security reports are reviewed to determine their scope, severity, and potential customer impact. When a confirmed issue affects customer data or app security, MayaTech Solutions will work to contain the issue, remediate it, and communicate with affected customers when required.

    Please do not publicly disclose a suspected vulnerability before MayaTech Solutions has had a reasonable opportunity to investigate and address it.

  • Report a security concern

    To report a suspected vulnerability or security incident, email:

    support@mayatechsolutionsllc.com

    Use the subject line:

    Security Report — Scrumpacity

    Please include:

    • A description of the issue

    • The affected feature or page

    • Steps needed to reproduce it

    • The potential security impact

    • Relevant screenshots or sanitized logs

    • Your preferred contact information

    Do not send passwords, API tokens, authentication cookies, private keys, or unnecessary customer data.

Privacy

Additional information

For information about personal-data handling, retention, and customer rights, review our Privacy Policy.

For product assistance, visit our Support page or email support@mayatechsolutionsllc.com.

Last updated: September 17, 2026