Katabarwa Labs
Security

Your data stays in your tenant. That is the whole design.

We operate no backend. There is no Katabarwa Labs server that your Jira, Confluence, or Azure data is sent to, because there is nowhere for it to go.

Atlassian apps

Built on Forge, inside your site

Azure apps

Managed applications in your subscription

Scopes by app

What each Atlassian app asks for

Access Governance Reporter read:jira-work, read:jira-user, storage:app one opt-in write path
Access Snapshot & Drift read:jira-work, read:jira-user, manage:jira-configuration, storage:app one opt-in write path
Compliance Log Vault read:audit-log:jira, read:user:jira, storage:app read-only
Inactive-User Hygiene read:jira-user, read:jira-work, storage:app one opt-in write path
Orphaned-Owner Cleanup read:jira-user, read:jira-work, storage:app read-only
Portal Governance for JSM read:servicedesk-request, manage:servicedesk-customer, read:jira-work / read:jira-user, storage:app one opt-in write path
Notification Log for JSM read:servicedesk-request, read:jira-work / read:jira-user, storage:app read-only
Assets Export Manager for JSM read:cmdb-schema:jira / read:cmdb-type:jira / read:cmdb-object:jira, read:servicedesk-request, storage:app one opt-in write path
Attachment Cleanup for Confluence read:space:confluence / read:page:confluence, storage:app one opt-in write path
Page-Restriction Governance read:space:confluence / read:page:confluence, storage:app one opt-in write path
Project Export & Backup read:jira-work, read:jira-user, storage:app, manage:jira-project, manage:jira-configuration one opt-in write path
Crisp Diagrams storage:app, read:content-details:confluence / write:attachment:confluence, read:attachment:confluence one opt-in write path
Security policy

Secure development practices

This is our published security policy. It backs the answers on every Marketplace listing's Privacy and Security tab and is reviewed at least annually. Last reviewed: September 2026.

Vulnerability disclosure

We want to hear about security issues in any Katabarwa Labs app. Send reports to support@llmgraph.ai with the app name, the affected version if known, and steps to reproduce. This is the same security contact listed on every Marketplace listing.

Incident response commitment

If we confirm a security incident affecting a Katabarwa Labs app, we commit to notifying Atlassian and every affected customer within 48 hours of confirming the incident, and to keeping them updated until it is resolved. Our incident response plan:

  1. Detect and triage. Within 24 hours of becoming aware of a possible incident we confirm whether it is real, which apps and versions are affected, and whether any customer data could have been exposed.
  2. Contain. Publish a patched version or withdraw the affected version from the Marketplace. Because our apps run inside the customer's own tenant with no servers of ours in the path, there is no Katabarwa Labs infrastructure to isolate.
  3. Notify within 48 hours. Report the confirmed incident to Atlassian through the Ecosystem security process and email every affected customer's listed contacts, describing what happened, what data or functionality was affected, what we have done, and what, if anything, they need to do.
  4. Remediate and verify. Fix the root cause, test it, redeploy, and confirm the fix with the reporter where one exists.
  5. Learn. Write a post-incident summary with timeline, root cause, and the change that prevents a repeat, and update this policy if a control failed.

Where a law or an Atlassian or Microsoft partner agreement requires a shorter notification window, the shorter window applies.

Security contact

support@llmgraph.ai for vulnerability reports, security questionnaires, and incident questions. Our privacy policy is at katabarwalabs.dev/privacy.