Data Security Statement

Effective Date: February 6, 2026

1. Overview

At Plugio, data security is fundamental to how we build our products. Our Atlassian and monday.com visualization apps have been designed with a security-first approach: we do not collect, store, process, or transmit any data. This document outlines our security posture and architecture.

2. Architecture: No Data Collection

The Plugio plugin operates entirely within your Atlassian environment. Our architecture ensures:

3. Data Flow

The data flow within our Plugin is straightforward and contained:

  1. The user configures a gadget on their dashboard (e.g., selecting a JQL filter or a project metric).
  2. The gadget configuration is stored by the product's own dashboard system — not by Plugio.
  3. When the dashboard loads, the Plugin reads the configured data using standard Atlassian APIs.
  4. The Plugin renders the data as a visual widget (gauge, counter, or progress bar) directly in the browser.

At no point does data leave your Atlassian instance through the Plugin.

4. What We Do Not Have

5. Minimal Permissions

Every Plugio app requests only the read scopes it needs to display your data — the exact list is shown by Atlassian on each Marketplace listing and at install time. All our Jira apps are built on Atlassian Forge and make no network calls outside Atlassian; where Atlassian has verified this, the listing carries the "Runs on Atlassian" badge. Issue data is read with the viewing user's own permissions where the app surface allows it, so our apps never widen what a user can see. Our monday.com widgets follow the same model: board data is read through monday.com's own APIs, rendered in your browser, and configuration is stored in your monday.com account.

6. Atlassian Security Compliance

As an Atlassian Marketplace app, Plugio adheres to Atlassian's security requirements for marketplace vendors. The Plugin is distributed through the Atlassian Marketplace and is subject to Atlassian's review processes.

7. Your Data Stays with Atlassian

Your data remains under the control of your Atlassian instance at all times. The security of your underlying data is governed by Atlassian's own security practices and your organization's administration policies. Plugio does not alter, affect, or introduce any additional risk to your data security posture.

8. Vulnerability Reporting

If you believe you have discovered a security vulnerability in the Plugio plugin, please report it to us promptly. We take all reports seriously and will investigate and respond as quickly as possible.

Email: [email protected]

9. Changes to This Statement

We may update this Data Security Statement to reflect changes in our practices or for other operational, legal, or regulatory reasons. Any updates will be posted on this page with an updated effective date.

10. Contact Us

For any questions about our data security practices, please contact us at:

Email: [email protected]