Trust Center
Facts an auditor can check. Every Claervo app is a Forge-only application: it runs on Atlassian infrastructure, stores only what it needs in Forge storage and never calls anything outside Atlassian.
Where code runs
Forge functions inside Atlassian's cloud. No Claervo-operated servers, containers or databases exist for these apps.
What is stored
Findings with masked samples and one-way hashes, policies, daily snapshots and an audit trail, all in Forge storage scoped to your site.
What is never stored
Raw personal data, request or page content, attachments, passwords, tokens.
Egress
None. The manifests declare no external permissions; the apps are eligible for the Runs on Atlassian program.
Access
Administrator pages are served only to product administrators; the apps never act as a user and never ask for account consent.
Deletion
Uninstalling the app deletes its Forge storage. Findings can also be reset from the app at any time.
Scope ledger
| read:jira-work | Read work items and comments in scoped projects |
| write:jira-work | Write redaction markers and the review label |
| storage:app | Findings, policy and audit trail in Forge storage |
| read:page / blogpost / comment:confluence | Read content to scan |
| write:page / blogpost / comment:confluence | Publish the redacted version |
| read:space:confluence | List spaces for scoping |
| storage:app | Findings, policy and audit trail in Forge storage |
| read:jira-work | Count work items and check usage before a change |
| manage:jira-configuration | Read fields, workflows, schemes; apply confirmed cleanup |
| manage:jira-project | Releases and components per project |
| storage:app | Findings, snapshots and audit trail |
| read:jira-work | Read request metadata and sharing fields |
| write:jira-work | Apply approved remediation |
| read:servicedesk-request / read:customer:jira-service-management | Organizations and participants |
| storage:app | Policies, findings and sanitized evidence |