Architecture and service boundaries

NexiStack First Line AI is a Rovo agent with a Forge action for retrieving Jira ticket context. The action runs in Atlassian Forge and calls Jira REST APIs. The current app manifest declares no remote backend or external network destinations.

Atlassian operates the underlying platform and its infrastructure controls. Nexi Stack maintains the app code and configuration. Customer administrators manage site access and Jira permissions. This policy does not claim an independent security certification, audit or Marketplace trust badge.

Authentication and authorisation

The action requires an authenticated principal from Forge execution context. Jira requests run with asUser(), respecting the current user’s Jira access. There is no fallback to app-level requests when access is denied. A ticket key is validated before it is used.

The agent is instructed not to request passwords, API tokens or authentication codes, or to treat identity supplied in chat as authenticated identity.

Declared permissions and supported operations

The current manifest requests read:jira-work, write:jira-work and read:jira-user. The implemented action uses read requests only. No ticket creation, modification, deletion or comment-posting action is exposed in this version.

Administrators should review permissions on the installation consent screen and assess the app under their organisation’s requirements. This policy describes the current implementation and does not imply that every declared scope is used.

Data handling and response limits

The implemented action does not persist ticket content in an app database. It retrieves selected fields and one page of up to 20 comments, with limits on description and comment-body lengths. It does not download attachment content.

Explicit application logs record operational stages, HTTP status codes and context-presence flags rather than ticket bodies or credentials. Consult Atlassian for platform logging, retention, encryption, residency and Rovo AI-processing details. See our privacy policy for the distinction between app data and support correspondence.

AI guidance and sensitive information

The agent is instructed to treat retrieved tickets and comments as source content, not overriding instructions; avoid unnecessary personal information; disclose incomplete results; and warn about suspected secrets without reproducing them. These instructions reduce risk but do not guarantee perfect AI behaviour.

Review outputs before acting. Do not supply credentials. Follow your organisation’s incident channels for urgent security concerns and its approval procedures for administrative changes.

Report a vulnerability

Email edson@nexistack.com with the subject Security report – First Line AI. Include the affected version, a description, impact and safe reproduction steps. Do not send live credentials, customer ticket exports or exploit material containing unnecessary personal data.

Request a secure exchange method if sensitive evidence is necessary. Test only environments and data you are authorised to assess; avoid destructive tests or access to other users’ data. Nexi Stack will assess the report and coordinate appropriate investigation and remediation. No guaranteed response or resolution SLA is stated here.

Incident coordination and updates

If you suspect an active incident, notify your organisation’s security team through its established channel and contact Nexi Stack for app-specific concerns. We assess reports, coordinate with the relevant platform provider where needed, and communicate confirmed impact and required action to affected contacts where appropriate and required.

Last updated: 5 October 2026. Contact us for additional security review information; certification and contractual commitments must be confirmed separately.