Synapse Security and Data
Last updated
Provide a clear security and data-handling view for enterprise review.
Security, risk, and compliance teams
Jira administrators approving app rollout
Access to Synapse functional documentation
Understanding of your Jira permission model
Confirm what data Synapse reads from Jira issue context.
Confirm when Synapse writes data back to Jira.
Review runtime and token model.
Confirm what preferences are stored and where.
Include this page in internal security approval records.
Jira issue summary
Jira issue description (ADF and plain text)
Jira comments
Jira labels
Jira issue type
Jira project information
Subtasks linked to the current issue (only in create-subtasks mode)
Creation status outputs in UI (created keys and errors)
Runs as a Forge app in the Atlassian-hosted runtime (Runs on Atlassian eligible)
Synapse runs fully on Atlassian Forge with no external backend or external storage.
Uses minimal scopes: read:jira-work, write:jira-work, read:app-user-token
Jira credentials are not stored
Browser localStorage: auto-generate-on-open preference
Logs: redacted logging approach for sensitive fields
Security reviews often miss browser-side storage; include localStorage in assessments.
Write permissions are required for create-subtasks mode.
Last updated