Security & Compliance
Vendor: BuzzClan · Last updated: June 2026
This page describes the security model and practices of the ReleaseScribe AI app ("the App") on Atlassian Cloud. For how the App handles data and personal information, see the Privacy Policy.
Security at a glance: ReleaseScribe AI runs entirely on the Atlassian Forge platform with zero data egress. It stores no customer data, holds no credentials or secrets of its own, and makes no network calls outside Atlassian. It inherits Atlassian's certified platform security controls ("Runs on Atlassian").
Platform and hosting
- The App is built on and runs entirely within Atlassian Forge. All compute, data processing, and AI execution occur inside Atlassian's infrastructure.
- The App provisions no servers, databases, or external services of its own.
- It inherits Atlassian's hosting, network, isolation, and compliance controls (Atlassian Cloud certifications and the Forge security model).
Authentication and authorization
- All Jira reads and the Confluence write run as the signed-in user, so the App can only access data that user is already permitted to see — it cannot escalate privileges.
- The App requests only the minimum permission scopes required:
read:jira-work,read:jira-user,read:sprint:jira-software,read:board-scope:jira-software,write:page:confluence,read:space:confluence. - The App holds no credentials or API keys of its own and stores no secrets.
Data handling and storage
- The App stores no customer data — no database, cache, or persistent log of your Jira or Confluence content.
- Selected issue data exists only transiently in memory for the duration of a single generation request and is discarded when it completes.
- The only durable output is the Confluence page you explicitly publish, which lives in your own Confluence instance.
AI processing
- AI generation uses Atlassian's native Forge LLM (Claude); prompts and responses are processed inside Atlassian's platform.
- No content is sent to BuzzClan servers, any external AI service, or any third party.
Network and egress controls
- The App declares no external egress permissions and makes no outbound network requests outside Atlassian — the basis for the "Runs on Atlassian" designation.
- There is no external endpoint, no bring-your-own-key, and no third-party integration.
Secure development and updates
- The App is distributed exclusively through the Atlassian Marketplace and updated via Atlassian's standard app-update mechanism.
- Any change to the App's permission scopes requires explicit administrator re-consent before it takes effect.
Vulnerability reporting
- Please report suspected security issues to info@buzzclan.com. We acknowledge reports and respond promptly, and we ask reporters to allow reasonable time for remediation before public disclosure.
Incident response
- Because the App stores no customer data, there is no separate data store to be breached.
- In the event of a platform-level security incident, we coordinate with Atlassian and notify affected site administrators as appropriate.
Changes to this policy
We may update this page to reflect changes to the App or to security practices; material changes are reflected by updating the "Last updated" date above.
Contact
- Security: info@buzzclan.com
- General / support: info@buzzclan.com



