Since 2016, JiBrok has served 1,000+ companies on Atlassian Marketplace. We undergo rigorous independent SOC 2 Type II audits to demonstrate our commitment to protecting customer data.
SOC 2 reports are independent third-party examination reports that demonstrate how JiBrok achieves key compliance controls and objectives. These reports are based on the existing Trust Services Criteria (TSC) from the American Institute of Certified Public Accountants (AICPA).
The purpose of SOC 2 is to evaluate our information systems relevant to:
JiBrok undergoes rigorous independent SOC 2 audits conducted by a reputable certified public accountant (CPA) firm on a regular basis. These audits evaluate whether our compliance controls are designed appropriately and are operating effectively over a specified period.
By achieving and maintaining SOC 2, JiBrok demonstrates a strong commitment to protecting customer data and adhering to industry standards. SOC 2 attestation examinations follow the SSAE 18 standard (section AT-C 105 and 205) governed by the AICPA. Our compliance controls are regularly assessed to ensure that we:
We provide access to our detailed SOC 2 Type 2 Report upon request, as well as publicly available SOC 3 and CAIQ Lite documentation.
JiBrok apps are built on Atlassian Forge - a serverless platform that runs entirely within Atlassian's infrastructure. This architecture eliminates the traditional attack surface that penetration testing addresses: there are no JiBrok-owned servers, databases, or network endpoints to test.
All Marketplace apps undergo Atlassian's security review process before publication. This review evaluates app permissions, data access patterns, and compliance with Atlassian's security requirements.
JiBrok Studio participates in the Atlassian Marketplace Security Bug Bounty Program - a crowdsourced vulnerability discovery program managed by Atlassian through the Bugcrowd platform. Security researchers are invited to test our apps and report vulnerabilities.
The Forge platform provides built-in security guarantees including tenant isolation, scoped permissions, encrypted storage, and zero external network access. These protections are managed and maintained by Atlassian.