Information Security Policy

Information Security Policy

 

  1. Purpose & Scope

This Policy establishes the security principles, controls, and responsibilities for all Optimizory Atlassian Marketplace applications. Optimizory Technologies Private Limited is certified to ISO/IEC 27001:2022 and ISO 9001:2015, and is an official Atlassian and monday.com Marketplace partner.

Scope covers:

  • All application releases, source code, build artifacts, and operational tooling.

  • All personnel, contractors, and service providers with access to application code or pipelines.

  • Application configuration settings and user preferences stored in Atlassian Forge Storage.

  1. Data Model & Hosting Architecture

Optimizory's applications are built exclusively on Atlassian Forge, a managed serverless platform. No bespoke servers, databases, or networking are operated by Optimizory, with the exception of RMsis Cloud , whose data is maintained on AWS servers operated by Optimizory. A substantial portion of security controls (data-centre security, encryption, tenant isolation, patching) are inherited from Atlassian and covered by Atlassian's SOC 2 Type II and ISO/IEC 27001 programmes.

Critical data-model commitments:

  • No customer personal data, or business content is stored by Optimizory or transmitted outside the customer's Atlassian instance for Forge-based applications.

  • The only data stored by the applications is held in Atlassian Forge Storage scoped to the customer's own instance.

  • No data leaves the customer's Atlassian environment. All stored data remains under Atlassian's and the customer's control.

  • Optimizory does not act as a sub-processor of personal data; no cross-border data transfers are introduced by Optimizory's applications.

  1. Security Controls

Control Domain

Optimizory Control

Access Control

MFA mandatory on all source code, pipeline, and console access. Least-privilege; quarterly review. Access revoked within 1 business day of role change; immediately for involuntary exits. No shared accounts. Segregation of duties: no single person authors, approves, and publishes a release.

Secure Development (SSDLC)

Mandatory peer review for all code. CI gates: lint, unit, integration, SAST must pass before merge. Security-sensitive changes require an additional independent reviewer. OWASP Top 10 and ASVS referenced. Forge manifest scopes minimised at design time.

Dependency Management

Continuous CVE scanning (npm audit + commercial scanner). SLA-bound remediation: Critical ≤ 72 hrs; High ≤ 7 days. Emergency release process for critical vulnerabilities.

Secrets Management

Secrets stored in purpose-built secret stores (Forge environment config; CI provider secrets). No secrets in source code. Pre-commit scanning in place. Rotation on personnel change and annually.

Endpoint Security

Full-disk encryption, automatic screen lock, current OS patches, and endpoint protection required on all developer devices. Lost/stolen devices reported within 4 hours; remote wipe invoked.

Release Management

Staged release validation before publication. Rollback available within minutes via Marketplace console. Emergency change process: peer review mandatory; CTO verbal approval; written ratification within 24 hrs.

Personnel

Background checks for personnel with code/pipeline access. Confidentiality obligations survive termination. Security awareness training on joining and annually. Engineering team completes OWASP-specific training.

 

  1. Roles & Responsibilities

Role

Responsibility

CTO

Owns this Policy; approves exceptions; chairs incident reviews.

Engineering Lead

SSDLC, code review standards, dependency hygiene, manifest scope review.

Incident Response Coordinator

Declares incidents; owns incident timeline; drives customer communications.

Release Manager

Marketplace operations: publish, rollback, emergency release.

Support Lead

Triages customer reports; escalates security signals immediately.

 

  1. Compliance & Certifications

  • ISO/IEC 27001:2022 — certified (information security management system).

  • ISO 9001:2015 — certified (quality management).

  • CAIQ-Lite — cloud security self-assessment completed.

  • OWASP Top 10 & ASVS — referenced for application security verification.

  • Atlassian Marketplace Security Requirements — adhered to at every release.

  1. Policy Review & Approval

Reviewed annually and additionally upon: (a) any Sev-1/Sev-2 incident, (b) material change to application architecture, (c) change in applicable law. Approval authority: Chief Technology Officer, Optimizory Technologies Private Limited.