Security & Compliance
Security & Compliance
Section titled “Security & Compliance”Armada is designed with security and compliance at its core, suitable for enterprise deployments in regulated industries.
SOC 2 Type II Compliance
Section titled “SOC 2 Type II Compliance”Armada maintains SOC 2 Type II certification, covering:
- Security: Protection against unauthorized access
- Availability: System uptime commitments
- Processing Integrity: Accurate data processing
- Confidentiality: Data protection controls
- Privacy: Personal information handling
Trust Center
Section titled “Trust Center”Access our full Trust Center for:
Data Security
Section titled “Data Security”Data Storage
Section titled “Data Storage”| Data Type | Location | Encryption |
|---|---|---|
| Campaign state | Jira entity properties | At-rest (Jira) |
| Fleet config | Forge Storage | At-rest (Atlassian) |
| User preferences | Forge Storage | At-rest (Atlassian) |
| Audit logs | Jira issue comments | At-rest (Jira) |
Data Residency
Section titled “Data Residency”- Default: United States
- Enterprise: Custom data residency (US, EU, APAC)
Contact [email protected] for data residency requirements.
Encryption
Section titled “Encryption”- All API calls use TLS 1.3
- Jira credentials stored in OS keychain
- No sensitive data in logs (PII scrubbing enabled)
Access Control
Section titled “Access Control”User Permissions
Section titled “User Permissions”Armada respects Jira’s existing permission model:
| Action | Required Permission |
|---|---|
| Launch campaign | Create issues |
| View campaign | Browse projects |
| Approve campaign | Administer projects |
| Configure fleet | Administer projects |
| Manage templates | Administer projects |
Role-Based Access Control (RBAC)
Section titled “Role-Based Access Control (RBAC)”Enterprise plans include:
- Custom roles with granular permissions
- Team-scoped access
- Audit logging of permission changes
Audit Logging
Section titled “Audit Logging”What Gets Logged
Section titled “What Gets Logged”Every significant action is recorded:
{ "timestamp": "2024-01-15T10:30:00Z", "action": "CAMPAIGN_LAUNCHED", "user": "user-123", "campaign": "PROJ-100", "children": 45, "metadata": { "strategy": "LINKED_ISSUE", "approvalRequired": true }}Log Retention
Section titled “Log Retention”- Standard: 90 days
- Enterprise: Configurable up to 7 years
Export Audit Logs
Section titled “Export Audit Logs”# Via API (Enterprise)GET /rest/armada/1.0/audit?from=2024-01-01&to=2024-01-31
# Via UISettings > Governance > Audit Log > ExportVulnerability Management
Section titled “Vulnerability Management”Security Updates
Section titled “Security Updates”- Critical vulnerabilities patched within 24 hours
- Regular dependency updates (monthly)
- Security advisories published at github.com/armada/security
Responsible Disclosure
Section titled “Responsible Disclosure”We welcome responsible disclosure of security vulnerabilities:
- Email [email protected]
- Include detailed reproduction steps
- Allow 48 hours for initial response
- We commit to not take legal action against good-faith researchers
Bug Bounty Program
Section titled “Bug Bounty Program”Enterprise customers have access to our bug bounty program:
- Critical: $10,000
- High: $5,000
- Medium: $1,000
- Low: $250
Compliance Mappings
Section titled “Compliance Mappings”| Requirement | Implementation |
|---|---|
| Right to access | Export via API |
| Right to erasure | Campaign deletion |
| Data portability | JSON export available |
| Consent | Permission-based |
| Safeguard | Implementation |
|---|---|
| Administrative | Access controls, RBAC |
| Physical | Atlassian cloud infrastructure |
| Technical | Encryption, audit logging |
| Organizational | Business associate agreements |
ISO 27001
Section titled “ISO 27001”Armada aligns with ISO 27001 controls:
- A.9.4 - Access control
- A.12.4 - Logging and monitoring
- A.18.1 - Compliance with laws
Security Best Practices
Section titled “Security Best Practices”For Administrators
Section titled “For Administrators”-
Install from trusted source only
- Use official Atlassian Marketplace
-
Review permissions regularly
- Quarterly access audits
- Remove unused team members
-
Enable audit logging
- Monitor for suspicious activity
- Set up alerts for bulk operations
-
Keep templates updated
- Review mission templates annually
- Remove outdated configurations
For Users
Section titled “For Users”-
Verify campaign targets
- Double-check issue selection
- Review affected teams
-
Use approval workflows
- Enable for sensitive campaigns
- Set appropriate thresholds
-
Report issues
- Use “Report Issue” in Armada panel
- Contact admin for urgent problems
Incident Response
Section titled “Incident Response”Suspected Breach?
Section titled “Suspected Breach?”- Immediately notify [email protected]
- Preserve evidence - don’t delete logs
- Document timeline of events
- We’ll respond within 4 hours
Containment Steps
Section titled “Containment Steps”- Disable affected user accounts
- Revoke API tokens
- Freeze non-essential operations
- Begin forensic investigation
Recovery
Section titled “Recovery”- Identify and patch vulnerability
- Restore from known-good backup
- Verify system integrity
- Resume operations with monitoring
Compliance Reports
Section titled “Compliance Reports”Available Documents
Section titled “Available Documents”| Document | Availability | Request |
|---|---|---|
| SOC 2 Type II | Enterprise | [email protected] |
| Penetration Test | Enterprise | [email protected] |
| Privacy Policy | All | Link |
| Terms of Service | All | Link |
| Data Processing Agreement | Enterprise | [email protected] |
Custom Compliance
Section titled “Custom Compliance”Need specific compliance documentation?
- Custom DPA with additional terms
- Right to audit clauses
- Specific security attestations
Contact [email protected]