Security policy

ESU Security Policy

Effective Date: 01.08.2026

Introduction

Security is foundational to how APTIS GmbH & Co. KG (“APTIS”, “we”, “our”) builds and operates the ESU Jira App. This Security Policy provides customers, prospects, and the Atlassian Marketplace ecosystem with an overview of the technical and organizational measures APTIS applies to protect information supporting the ESU Jira App. It is published in addition to, and should be read alongside, our Privacy Policy and Data Processing Agreement.

This Security Policy is a public summary of APTIS’ internal Information Security Management System (ISMS) and does not disclose implementation-specific details that could undermine the effectiveness of our controls.

Our Security Program

APTIS maintains a formal Information Security Management System (ISMS), scaled appropriately to our size and operating model, and governed by a dedicated Information Security Policy together with a full set of supporting policies covering access control, asset management, data management, cryptography, third-party security, secure software development, operations security, physical security, incident response, business continuity, and risk management.

APTIS is pursuing SOC 2 Type I certification, with SOC 2 Type II planned to follow. Our security program is designed and continuously reviewed against the SOC 2 Trust Services Criteria and the applicable Atlassian Marketplace Security Requirements.

Infrastructure & Hosting

APTIS operates a cloud-first infrastructure model and does not operate its own data centers or server infrastructure. The ESU Jira App is built primarily on Atlassian Forge, a fully managed cloud platform. Atlassian Connect is supported only as a legacy option for existing customers during a transition period and is not available for new installations. For Jira Data Center deployments, the application runs entirely within the customer’s own infrastructure, which the customer is responsible for securing.

Where APTIS relies on approved cloud service providers, security responsibilities are shared: providers are responsible for the security of the underlying infrastructure, while APTIS remains responsible for secure configuration, identity and access management, and application-level security.

Security responsibilities are shared between APTIS and its approved cloud service providers. Providers are responsible for the security of the underlying infrastructure they operate, including physical security, hardware, and platform availability. APTIS remains responsible for the secure configuration of the services it uses, identity and access management, application-level security, and the protection of the data it processes. 

Access Control & Authentication

Access to APTIS systems is granted based on the principles of least privilege and need-to-know, following formal authorization. Multi-factor authentication is enforced across business systems wherever technically supported, and Single Sign-On is used where available. Access rights are formally reviewed at least annually, and access is revoked promptly when no longer required.

Encryption

Information is encrypted in transit using industry-standard protocols (TLS) and at rest using the native encryption capabilities of our approved cloud service providers. Credentials and application secrets are never stored in source code repositories.

Secure Software Development

APTIS follows a secure software development lifecycle in which security requirements are considered at every stage — planning, implementation, code review, testing, and release. All production code changes undergo mandatory peer review before deployment. Dependencies and application code are continuously scanned for known vulnerabilities as part of our automated development pipeline.

Vulnerability Management & Security Testing

APTIS operates a structured vulnerability management process with severity-based remediation timeframes aligned to the Atlassian Marketplace Security Bug Fix Policy. Infrastructure and cloud configurations are scanned regularly, and a human-led penetration test of the production environment is performed at least annually by qualified internal personnel or an independent third-party security firm.

Logging & Monitoring

APTIS relies on the built-in logging and monitoring capabilities of its approved cloud service providers to maintain visibility into activity within the ESU Jira App environment, supporting the timely detection of, and response to, potential security events.

Incident Response

APTIS maintains a formal Incident Response Plan defining escalation paths, severity classification, and response procedures. In the event of a confirmed incident affecting customer data, APTIS is committed to notifying affected customers without undue delay, and, where a personal data breach is confirmed, in line with applicable legal notification timeframes.

Business Continuity & Disaster Recovery

APTIS relies on the availability, resilience, and disaster recovery capabilities of its established cloud service providers rather than operating independent infrastructure. Business continuity and disaster recovery procedures are formally tested at least annually.

Third-Party & Sub-processor Management

New vendors and sub-processors undergo a formal risk assessment and require documented approval before integration into the ESU Jira App environment. Approved providers are reviewed on an ongoing basis to confirm they continue to meet APTIS’ security standards. A current list of sub-processors is available through our Data Processing Agreement.

Personnel Security

All APTIS personnel and approved contractors are subject to confidentiality obligations, complete information security awareness training before or shortly after gaining system access, and at least annually thereafter, and are bound by our Code of Conduct. Access to customer information is limited to authorized personnel with a legitimate business need.

Data Minimization

APTIS applies data minimization as a core operating principle: we do not intentionally collect customer content through the standard functionality of the ESU Jira App, and information voluntarily provided for support purposes is limited to what is necessary to resolve the reported issue. Further detail is available in our Privacy Policy.

Reporting a Security Concern

If you believe you have identified a security vulnerability affecting the ESU Jira App, please report it to [security contact email]. We ask that you provide sufficient detail to reproduce the issue and refrain from public disclosure until we have had a reasonable opportunity to investigate and remediate.

Changes to this Security Policy

APTIS may update this Security Policy from time to time to reflect changes in our security practices, infrastructure, or applicable requirements. The current version is always published together with its effective date.

Table of Contents