Security Policy
How ChangeLens is designed to minimize data exposure, protect Jira access, and handle security issues.
Scope
This policy describes the security practices for ChangeLens, a Jira Cloud app published by MintedTools. It covers the ChangeLens application, its Atlassian Forge deployment, and the support processes used for security issues.
Hosting and architecture
ChangeLens is hosted on Atlassian Forge. MintedTools does not operate a separate application backend or external database for ChangeLens. The app does not use Forge Remote and does not send Jira description or changelog content to external MintedTools servers.
Jira access and permissions
ChangeLens is designed for read-only comparison of Jira description history. It requests the Jira read scope needed to retrieve issue descriptions and changelog information and does not request permission to edit Jira work items. Jira API requests made by the app are executed in the current user's Jira permission context.
Customer data
ChangeLens processes Jira description and changelog data only as needed to generate comparisons in the app experience. MintedTools does not maintain an external database of Jira descriptions, changelog entries, or comparison results. For additional details, see the ChangeLens Privacy Policy.
Credentials and secrets
ChangeLens does not ask users to provide Atlassian passwords, Personal Access Tokens, API keys, or third-party credentials. Sensitive credentials are not intentionally written to application logs or exposed in client-side URLs.
Input and content handling
ChangeLens does not provide arbitrary HTML or script execution features. User interactions are limited to selecting existing Jira revisions and comparison views. Jira content is presented through the app interface rather than executed as user-supplied code.
Dependencies and vulnerability management
MintedTools reviews the software dependencies used by ChangeLens and applies security updates when relevant issues are identified. Security issues affecting ChangeLens are evaluated based on severity, exploitability, customer impact, and Atlassian Marketplace requirements.
Security incidents
If MintedTools confirms a security incident or critical vulnerability that materially affects ChangeLens customers, we will investigate, remediate where applicable, and notify Atlassian and affected customers as appropriate. Response and communication may depend on the nature of the issue and any Atlassian platform dependencies.
Reporting a security issue
Report suspected ChangeLens security issues to [email protected]. Please include enough detail to reproduce or investigate the issue, but avoid sending passwords, access tokens, or unnecessary confidential Jira content.
Support and response targets
General support hours and response targets are available in the ChangeLens Support SLA. Security reports may be prioritized differently based on severity and potential customer impact.
Policy updates
MintedTools may update this policy as ChangeLens, Atlassian requirements, or our security practices evolve. Material changes will be reflected on this page.
Effective date: October 6, 2026.