Security and SOC Reports

Since 2016, JiBrok has served 1,000+ companies on Atlassian Marketplace. We undergo rigorous independent SOC 2 Type II audits to demonstrate our commitment to protecting customer data.

System and Organization Controls (SOC) 2

SOC 2 reports are independent third-party examination reports that demonstrate how JiBrok achieves key compliance controls and objectives. These reports are based on the existing Trust Services Criteria (TSC) from the American Institute of Certified Public Accountants (AICPA).

The purpose of SOC 2 is to evaluate our information systems relevant to:

  • Security
  • Availability
  • Processing Integrity
  • Confidentiality
  • Privacy

JiBrok undergoes rigorous independent SOC 2 audits conducted by a reputable certified public accountant (CPA) firm on a regular basis. These audits evaluate whether our compliance controls are designed appropriately and are operating effectively over a specified period.

Why SOC 2 Matters

By achieving and maintaining SOC 2, JiBrok demonstrates a strong commitment to protecting customer data and adhering to industry standards. SOC 2 attestation examinations follow the SSAE 18 standard (section AT-C 105 and 205) governed by the AICPA. Our compliance controls are regularly assessed to ensure that we:

  • Maintain consistent security practices
  • Address potential threats proactively
  • Continuously improve our policies and processes

Access Our Reports

We provide access to our detailed SOC 2 Type 2 Report upon request, as well as publicly available SOC 3 and CAIQ Lite documentation.

Security Testing & Validation

JiBrok apps are built on Atlassian Forge - a serverless platform that runs entirely within Atlassian's infrastructure. This architecture eliminates the traditional attack surface that penetration testing addresses: there are no JiBrok-owned servers, databases, or network endpoints to test.

Atlassian Security Review

All Marketplace apps undergo Atlassian's security review process before publication. This review evaluates app permissions, data access patterns, and compliance with Atlassian's security requirements.

Marketplace Bug Bounty Program

JiBrok Studio participates in the Atlassian Marketplace Security Bug Bounty Program - a crowdsourced vulnerability discovery program managed by Atlassian through the Bugcrowd platform. Security researchers are invited to test our apps and report vulnerabilities.

Forge Platform Security

The Forge platform provides built-in security guarantees including tenant isolation, scoped permissions, encrypted storage, and zero external network access. These protections are managed and maintained by Atlassian.

JiBrok Studio for Jira Cloud JiBrok Studio for Jira Cloud
JiBrok Message Field for Jira Cloud Message Field for Jira Cloud
JiBrok time in status Time in status for Jira Cloud
JiBrok Calculated fields Calculated fields (JBCF) for Jira Cloud
JiBrok Timer Timer field | SLA for Jira Cloud
JiBrok Stopwatch Stopwatch for Jira Cloud
JiBrok Time between dates Time between dates for Jira Cloud
JiBrok Fields panel for Jira Service Management (JSM) Fields panel for Jira Service Management (JSM)
JiBrok Display Linked Issues Display Linked Issues
User helper for JiBrok cloud apps User helper for JiBrok cloud apps
JiBrok message field Message field
JiBrok time in status Time in status | SLA | Timer | Stopwatch
JiBrok Switch to User + Delegating SU (Jira) Switch to User + Delegating SU (Jira)
JiBrok Calculated fields Calculated fields (JBCF)
rss
rss
rss