Org Explorer: Legal
Data security and privacy
Org Explorer is a Forge app for Jira Service Management. By design, all interaction with customer content is limited to the permissions of the logged-in user and the scopes declared in the app's Forge manifest.
- All customer content is processed and stored in Forge; nothing is stored externally unless explicitly configured by the customer.
- Configuration and non-identifying account information are stored in Forge unless the customer opts into external storage for integrations or support.
- No usage or tracking data is collected by third-party systems unless explicitly disclosed to and agreed by the customer.
Terms of Use
Chief Technology Solutions grants you, being an Atlassian customer (e.g. person or entity), a limited, worldwide, non-exclusive, non-transferable and non-sublicensable license to install Org Explorer.
Org Explorer is provided via the Atlassian Marketplace for Jira Service Management.
The app is provided on an "as is" and "as available" basis, without warranty of any kind, express or implied, except for those guarantees that cannot be excluded under Australian Consumer Law (ACL). The Atlassian Terms govern refunds.
Background sync is a compute-intensive feature powered by Atlassian Forge and is available exclusively on active commercial paid licences. Evaluation, trial, sandbox, and community licences do not include background sync. Chief Technology Solutions reserves the right to adjust sync frequency, apply sync quotas, or suspend sync access for any installation that places excessive load on the platform or that we reasonably determine is abusing the service. We will endeavour to notify affected customers before or promptly after taking such action.
You may not modify, reverse engineer, decompile or disassemble Org Explorer in whole or in part, or create any derivative works, unless otherwise expressly authorized in writing by Chief Technology Solutions.
Any dispute arising out of or in connection with this agreement shall be governed by and construed according to the laws of Australia and New South Wales.
Partner Security Policy
Org Explorer is developed and operated by Chief Technology Solutions and runs entirely on Atlassian Forge. The app does not use external third‑party hosting or analytics platforms.
Security incidents
Customers and partners should report suspected security issues via the Contact page or the responsible disclosure process linked in the app listing. We acknowledge reports promptly (typically within 24 hours), perform an initial triage, investigate and mitigate impacts, communicate status to affected parties, and conduct a post‑incident review.
Vulnerability management
- Reporting: We accept vulnerability reports through official channels and encourage reproducible details to assist investigation.
- Triage: Reports are triaged by severity (within 72 hours for confirmed issues) and assigned for remediation.
- Remediation: Fixes are developed, tested, and deployed on Forge. We prioritise high‑severity issues and follow coordinated disclosure practices where appropriate.
Key security controls
- Forge hosting: The app and customer data are hosted in Atlassian Forge; no customer content is stored externally unless explicitly configured by the customer.
- Access control: Principle of least privilege is applied to app scopes and user permissions; access is enforced via Atlassian authentication and project/organization permissions.
- Data protection: Data in transit is protected by TLS; data at rest is handled according to Forge storage controls and minimised by design.
- Monitoring & logging: Operational monitoring and logging detect service issues and suspicious activity; alerts trigger our incident response.
- Secure development: Secure coding practices, dependency scanning, and periodic security reviews help reduce vulnerabilities.
Date: June 2026