Information Security Policy
Purpose & Scope
This Policy establishes the security principles, controls, and responsibilities for all Optimizory Atlassian Marketplace applications. Optimizory Technologies Private Limited is certified to ISO/IEC 27001:2022 and ISO 9001:2015, and is an official Atlassian and monday.com Marketplace partner.
Scope covers:
All application releases, source code, build artifacts, and operational tooling.
All personnel, contractors, and service providers with access to application code or pipelines.
Application configuration settings and user preferences stored in Atlassian Forge Storage.
Data Model & Hosting Architecture
Optimizory's applications are built exclusively on Atlassian Forge, a managed serverless platform. No bespoke servers, databases, or networking are operated by Optimizory, with the exception of RMsis Cloud , whose data is maintained on AWS servers operated by Optimizory. A substantial portion of security controls (data-centre security, encryption, tenant isolation, patching) are inherited from Atlassian and covered by Atlassian's SOC 2 Type II and ISO/IEC 27001 programmes.
Critical data-model commitments:
No customer personal data, or business content is stored by Optimizory or transmitted outside the customer's Atlassian instance for Forge-based applications.
The only data stored by the applications is held in Atlassian Forge Storage scoped to the customer's own instance.
No data leaves the customer's Atlassian environment. All stored data remains under Atlassian's and the customer's control.
Optimizory does not act as a sub-processor of personal data; no cross-border data transfers are introduced by Optimizory's applications.
Security Controls
Control Domain | Optimizory Control |
Access Control | MFA mandatory on all source code, pipeline, and console access. Least-privilege; quarterly review. Access revoked within 1 business day of role change; immediately for involuntary exits. No shared accounts. Segregation of duties: no single person authors, approves, and publishes a release. |
Secure Development (SSDLC) | Mandatory peer review for all code. CI gates: lint, unit, integration, SAST must pass before merge. Security-sensitive changes require an additional independent reviewer. OWASP Top 10 and ASVS referenced. Forge manifest scopes minimised at design time. |
Dependency Management | Continuous CVE scanning (npm audit + commercial scanner). SLA-bound remediation: Critical ≤ 72 hrs; High ≤ 7 days. Emergency release process for critical vulnerabilities. |
Secrets Management | Secrets stored in purpose-built secret stores (Forge environment config; CI provider secrets). No secrets in source code. Pre-commit scanning in place. Rotation on personnel change and annually. |
Endpoint Security | Full-disk encryption, automatic screen lock, current OS patches, and endpoint protection required on all developer devices. Lost/stolen devices reported within 4 hours; remote wipe invoked. |
Release Management | Staged release validation before publication. Rollback available within minutes via Marketplace console. Emergency change process: peer review mandatory; CTO verbal approval; written ratification within 24 hrs. |
Personnel | Background checks for personnel with code/pipeline access. Confidentiality obligations survive termination. Security awareness training on joining and annually. Engineering team completes OWASP-specific training. |
Roles & Responsibilities
Role | Responsibility |
CTO | Owns this Policy; approves exceptions; chairs incident reviews. |
Engineering Lead | SSDLC, code review standards, dependency hygiene, manifest scope review. |
Incident Response Coordinator | Declares incidents; owns incident timeline; drives customer communications. |
Release Manager | Marketplace operations: publish, rollback, emergency release. |
Support Lead | Triages customer reports; escalates security signals immediately. |
Compliance & Certifications
ISO/IEC 27001:2022 — certified (information security management system).
ISO 9001:2015 — certified (quality management).
CAIQ-Lite — cloud security self-assessment completed.
OWASP Top 10 & ASVS — referenced for application security verification.
Atlassian Marketplace Security Requirements — adhered to at every release.
Policy Review & Approval
Reviewed annually and additionally upon: (a) any Sev-1/Sev-2 incident, (b) material change to application architecture, (c) change in applicable law. Approval authority: Chief Technology Officer, Optimizory Technologies Private Limited.