Skip to content

Security & Compliance

Armada is designed with security and compliance at its core, suitable for enterprise deployments in regulated industries.

Armada maintains SOC 2 Type II certification, covering:

  • Security: Protection against unauthorized access
  • Availability: System uptime commitments
  • Processing Integrity: Accurate data processing
  • Confidentiality: Data protection controls
  • Privacy: Personal information handling

Access our full Trust Center for:


Data TypeLocationEncryption
Campaign stateJira entity propertiesAt-rest (Jira)
Fleet configForge StorageAt-rest (Atlassian)
User preferencesForge StorageAt-rest (Atlassian)
Audit logsJira issue commentsAt-rest (Jira)
  • Default: United States
  • Enterprise: Custom data residency (US, EU, APAC)

Contact [email protected] for data residency requirements.

  • All API calls use TLS 1.3
  • Jira credentials stored in OS keychain
  • No sensitive data in logs (PII scrubbing enabled)

Armada respects Jira’s existing permission model:

ActionRequired Permission
Launch campaignCreate issues
View campaignBrowse projects
Approve campaignAdminister projects
Configure fleetAdminister projects
Manage templatesAdminister projects

Enterprise plans include:

  • Custom roles with granular permissions
  • Team-scoped access
  • Audit logging of permission changes

Every significant action is recorded:

{
"timestamp": "2024-01-15T10:30:00Z",
"action": "CAMPAIGN_LAUNCHED",
"user": "user-123",
"campaign": "PROJ-100",
"children": 45,
"metadata": {
"strategy": "LINKED_ISSUE",
"approvalRequired": true
}
}
  • Standard: 90 days
  • Enterprise: Configurable up to 7 years
Terminal window
# Via API (Enterprise)
GET /rest/armada/1.0/audit?from=2024-01-01&to=2024-01-31
# Via UI
Settings > Governance > Audit Log > Export

  • Critical vulnerabilities patched within 24 hours
  • Regular dependency updates (monthly)
  • Security advisories published at github.com/armada/security

We welcome responsible disclosure of security vulnerabilities:

  1. Email [email protected]
  2. Include detailed reproduction steps
  3. Allow 48 hours for initial response
  4. We commit to not take legal action against good-faith researchers

Enterprise customers have access to our bug bounty program:

  • Critical: $10,000
  • High: $5,000
  • Medium: $1,000
  • Low: $250

RequirementImplementation
Right to accessExport via API
Right to erasureCampaign deletion
Data portabilityJSON export available
ConsentPermission-based
SafeguardImplementation
AdministrativeAccess controls, RBAC
PhysicalAtlassian cloud infrastructure
TechnicalEncryption, audit logging
OrganizationalBusiness associate agreements

Armada aligns with ISO 27001 controls:

  • A.9.4 - Access control
  • A.12.4 - Logging and monitoring
  • A.18.1 - Compliance with laws

  1. Install from trusted source only

    • Use official Atlassian Marketplace
  2. Review permissions regularly

    • Quarterly access audits
    • Remove unused team members
  3. Enable audit logging

    • Monitor for suspicious activity
    • Set up alerts for bulk operations
  4. Keep templates updated

    • Review mission templates annually
    • Remove outdated configurations
  1. Verify campaign targets

    • Double-check issue selection
    • Review affected teams
  2. Use approval workflows

    • Enable for sensitive campaigns
    • Set appropriate thresholds
  3. Report issues

    • Use “Report Issue” in Armada panel
    • Contact admin for urgent problems

  1. Immediately notify [email protected]
  2. Preserve evidence - don’t delete logs
  3. Document timeline of events
  4. We’ll respond within 4 hours
  1. Disable affected user accounts
  2. Revoke API tokens
  3. Freeze non-essential operations
  4. Begin forensic investigation
  1. Identify and patch vulnerability
  2. Restore from known-good backup
  3. Verify system integrity
  4. Resume operations with monitoring

DocumentAvailabilityRequest
SOC 2 Type IIEnterprise[email protected]
Penetration TestEnterprise[email protected]
Privacy PolicyAllLink
Terms of ServiceAllLink
Data Processing AgreementEnterprise[email protected]

Need specific compliance documentation?

  • Custom DPA with additional terms
  • Right to audit clauses
  • Specific security attestations

Contact [email protected]