Security & Data Handling

Security & Data Handling

This page describes security and data-handling practices implemented in CFGORA today. It is not a certification or compliance statement.

OAuth-based Jira connection

CFGORA connects to Jira Cloud using Atlassian OAuth 2.0. You authorize access directly with Atlassian. We never see or store your Atlassian password.

Requested Jira access

CFGORA requests read access to Jira configuration and work, plus your Atlassian account identity, so it can run health scans. CFGORA does not modify Jira.

Read-only Jira behavior

All Jira access is read-only. CFGORA currently uses read-only Jira access and does not automatically modify your Jira configuration. It analyses configuration and audit signals, generates findings, and tracks recommended remediation plans internally. It does not create, update, or delete Jira issues, workflows, fields, or automation rules.

Encrypted connection credentials

Jira connection credentials are encrypted at rest. Short-lived session credentials are kept in HTTP-only cookies and are not exposed to the browser.

Server-side connection handling

Connecting to Jira, refreshing the connection, and running scans happen on CFGORA servers. Connection credentials are not returned in page responses or written to application logs.

Site isolation

Saved scans, findings, recommended remediation plans, alerts, and schedules are associated with a specific connected Jira site. Data for one connected site is not mixed with another.

Stored scan summaries and findings

When saved scans are enabled, CFGORA stores configuration health summaries, finding snapshots, and comparison metadata needed for trends and notifications. This data is stored in CFGORA, not in Jira.

Recommended remediation data stored in CFGORA

Recommended remediation plans and suggested improvements are tracked in CFGORA only. Marking a recommendation as completed does not change Jira configuration.

Reconnect Jira

If the Jira connection becomes invalid, CFGORA asks you to Reconnect Jira. Automatic scanning pauses until the connection is restored.

Automatic scanning

When automatic scanning is enabled, CFGORA runs one read-only scan per day for your connected Jira site. CFGORA runs one automatic scan per day for each enabled site, starting around 07:00 UTC. Actual scan times may vary. Automatic scanning requires a valid Jira connection.

Stripe billing

Checkout and the customer billing portal are opened from your signed-in CFGORA workspace. Stripe processes payment information. CFGORA stores only billing identifiers and subscription status, not card numbers or payment-method details. Payment notifications from Stripe are verified before any plan change is applied.

Product independence

CFGORA is an independent product and is not affiliated with or endorsed by Atlassian.

Jira and Atlassian are trademarks of Atlassian Pty Ltd.