Security Overview

Trust notes for Jira admins and platform teams

Baytek Agile Analytics is designed to feel easy to approve: Forge-native hosting, read-only Jira access, minimal storage, and no backend egress unless an admin opts into Slack or Teams alert webhooks.

Runs on Atlassian architecture

The app is built for Jira Cloud on Atlassian Forge, so execution and storage remain inside Atlassian-managed infrastructure rather than a separate publisher-hosted backend.

Read-only Jira access

Baytek Agile Analytics is designed for reporting and operational visibility. It reads project, sprint, workflow, and issue metadata without modifying Jira issues.

Minimal, opt-in egress

The backend makes no outbound network calls by default. The only external traffic the app can produce is a POST to a Slack or Microsoft Teams incoming-webhook URL that an admin explicitly configures for sprint alerts. No data is sent anywhere else.

Minimal storage model

Only lightweight configuration items such as workflow mappings and audit trail entries are stored in Forge Key-Value Storage. Analytics results are computed from live Jira data and are not persisted.

Quick technical snapshot

Platform: Atlassian Forge (Cloud only)
Permissions: Read-only Jira scopes plus app storage
Storage: Forge Key-Value Store for workflow config and audit trail only
Egress: None by default; optional Slack/Teams incoming-webhook POSTs only when an admin configures sprint alerts
Security posture: Runs on Atlassian aligned, encrypted storage, no external analytics backend
Support contact: support@baytekdev.com