RVS Security Policy

RVS Security Policy

RVS Softek is committed to protecting the security and integrity of our apps and the data of our customers. This policy applies to all RVS Atlassian apps.


1. Data Transfer

All apps are installed on the customer's Jira instance and do not send any data outside the customer's network, except for the limited configuration data described in Section 2 below for Cloud deployments.


2. Data Storage

Server / Data Center

All data collected and stored by the apps resides entirely within the customer's Jira database. No data is transmitted to RVS servers.

Cloud

For Cloud versions (except Capacity Planner), only the following non-sensitive configuration data is stored in our database:

  1. Plugin-level global settings (not user settings)

  2. Grouped Statuses (Time in Status Reports & Agile Tools apps only)

All other data is stored in the customer's Jira & Confluence database.

For the Capacity Planner app, we additionally store:

  1. User Name

  2. Capacity per day (as entered in the app)

  3. Team Holidays (as entered in the app)

  4. Sprint Name

  5. Team Capacity per day (as entered in the app)

Our Cloud database is hosted on the Akamai cloud platform, on nodes operating exclusively within the United States.


3. Security Incident Handling

We take security incidents seriously and follow a defined response process:

Detection & Triage — Upon identification, incidents are triaged to assess scope and severity.

Containment — Affected systems or components are isolated as quickly as possible to limit any potential impact.

Investigation & Remediation — The root cause is investigated and a fix is developed, tested, and deployed. For Cloud-hosted components, patches are applied promptly. For Marketplace app updates, releases are submitted through Atlassian's standard review process.

Customer Notification — If an incident affects customer data or app functionality, impacted customers are notified in a timely manner with details of what occurred and what steps have been taken.

To report a suspected security incident, contact us at support@rvsoftwares.in.


4. Vulnerability Management

Reporting — We welcome responsible disclosure of security vulnerabilities. If you discover a potential vulnerability in any RVS app, please report it to support@rvsoftwares.in . We ask that you provide sufficient detail to reproduce the issue and allow us reasonable time to respond before any public disclosure.

Triage — Reported vulnerabilities are reviewed and prioritized based on severity (following a risk-based assessment of potential impact and exploitability).

Remediation — We aim to address critical vulnerabilities as quickly as possible. Fixes are released through Atlassian Marketplace updates, and customers are encouraged to keep their apps updated to the latest version.

Third-Party Dependencies — We monitor our app dependencies for known vulnerabilities and apply updates as part of our regular development cycle.


5. Technical and Organizational Security Controls

Access Control

  • Access to our production systems and databases is restricted to authorized RVS personnel only.

Data Protection

  • Our apps are client-side by design — Jira/Confluence data is processed in the user's browser and never transmitted to RVS servers, minimizing exposure risk.

  • Any configuration data stored in our Cloud database is stored securely. Data in transit is protected using TLS encryption.

  • We do not store passwords, tokens, or other authentication credentials.

Infrastructure Security

  • Our Cloud infrastructure is hosted on Akamai, a platform that provides DDoS protection, network-level security, and physical security controls at its data centers.

  • Infrastructure access is controlled.

Secure Development

  • Security considerations are incorporated into our development process, including code review before release.

  • App updates go through Atlassian's Marketplace security review process prior to publication.

Organizational Controls

  • Security responsibilities are assigned within our team.

  • Employees with access to production systems are made aware of their security obligations.


6. Contact

For security-related questions, vulnerability reports, or incident notifications, please contact:

RVS Softek
📧 Email: support@rvsoftwares.in
🌐 Website: https://www.rvssoftek.com