Time in Status

Security & Privacy FAQ page

Certifications





ff62fc1c-2563-45b9-8dbd-f4c32f15d65c.jpg

SaaSJet is a Platinum Marketplace Partner


What does “Platinum partner” mean? According to annual gross sales ("Purchase Price" in Marketplace reports), a minimum $1M annual gross sales comprised a minimum of 35% from the cloud.




image-20240620-082852.png

Cloud Fortified


The Cloud Fortified Apps Program aims to serve our largest customers and those with more business-critical operating requirements for apps.




runson.png

Runs on Atlassian


This badge confirms that the app is built on Atlassian Forge and meets the technical requirements of the Runs on Atlassian program. Time in Status uses Atlassian-hosted infrastructure for eligible app functionality and supports Atlassian platform capabilities such as security, reliability, and data residency.

The badge was achieved following the complete migration of Time in Status to Forge, providing a secure and scalable foundation for future product development.


c8cdc5d3-3e5c-4d3c-a704-fc57737c7243.png

Marketplace Security Bug Bounty Program


A bug bounty program is one of the most powerful post-production tools for detecting vulnerabilities in applications and services.

Security



7658c570-3860-415f-985a-8d7059dd472a.png

System and Organization Controls - SOC 2


SOC 2 reports are independent third-party examination reports demonstrating how an organization achieves key compliance controls and objectives.

  • What Atlassian says about Trust Service Criteria (TSC) - read more

  • SaaSJet is SOC 2 Type 2 compliant - read more


image-20240410-184007.png


CAIQ-Lite

CAIQ Lite is a simplified version of the Consensus Assessments Initiative Questionnaire (CAIQ), which is designed to assess the security posture of cloud service providers.

Atlassian requires all Platinum, Gold, and Silver Marketplace Partners to complete the CAIQ-Lite questionnaire, which it then reviews.

  • What Atlassian says about the security of the cloud ecosystem - read more


a2d1093e-05c9-4cb2-aad5-9027daa58e56.png


Security Contact


If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please contact us at security@saasjet.com


Support



94d4c839-b06d-4f9c-a76a-890d39acd0d8.png


Working hours: Mon-Fri 24hrs GMT+3

Phone: +1 888 396 0501

Book a demo session: click to schedule an online free demo

Support portal: click to create a ticket

Help: Read the documentation

Where your data lives

Time in Status runs on Atlassian Forge. Your app data and report calculations are stored and processed inside Atlassian's own cloud infrastructure (Forge Storage and Jira) — not on SaaSJet servers. Because the app runs inside Atlassian's sandboxed runtime, data egress is limited by the platform itself.

The only information that reaches SaaSJet directly is what you deliberately send us — for example, a support request, or the billing/technical-contact details on your subscription — handled under the SaaSJet Privacy Policy.

FAQ


Data storage questions:

Q: Do we collect personal information?

A: We don’t collect any personal information while using our applications. We can store your personal information in 2 cases:

  • to reply to your request if you send it directly to us for some reason.

  • if your name and email are specified as your organization’s billing or technical contact during the subscription process.

We don’t gather it by ourselves. We see only the information you have specified.


Q: How is customer data processed?

A: We use it to generate reports in which user names appear as assignee, reporter, or in custom fields during Jira work-item processing. We access your work items according to the filters you select in the app, and based on the work-item history we perform the calculations needed to build your report. This processing runs inside the Forge runtime; the results are returned to you in the app. All other data is unidentified and hidden from us.


Q: What customer data do we store?

A: In Forge Storage (inside Atlassian), the app stores your app configuration only — report presets and their filters/JQL, work-schedule and permission settings, and the Atlassian account ID / public display name as it appears in a report. This stays inside Atlassian and is not sent to SaaSJet servers.

Separately, if you visit our website or contact support, standard technical information may be collected in that context.


Q: Where is customer data stored?

A: We do not store your personal data on our servers. Your Time in Status app data is stored and processed inside Atlassian's cloud (Forge Storage and Jira), in Atlassian's regional data systems. Following the complete migration to Forge, the app no longer routes your report data through SaaSJet-operated servers. Any data you send us directly (support requests, billing/technical contact) is handled by SaaSJet under the SaaSJet Privacy Policy and does not contain your Jira report content.


Q: How long do we store your data?

A: App data lives in Forge Storage and follows Atlassian's Forge hosted-storage data lifecycle — retention, soft-deletion after uninstall, and disposal are handled by Atlassian. Information you enter in the app (presets and your Atlassian account ID) persists until you or an authorized user deletes it. To request earlier removal, contact support@saasjet.com.


Q: Do you encrypt the data you store?

A: We do not store personal information about our customers (names, addresses, emails, accounts). App data in Forge Storage is encrypted at rest and in transit (TLS/SSL), managed by Atlassian's platform.

Common security questions:

Q: Do you have security officer in your company?

A: Yes, we have a security officer in the company. Contact at security@saasjet.com


Q: What is security monitoring strategy?

A: The Time in Status app runtime is hosted, isolated, and monitored by Atlassian's Forge platform, which handles platform-level security updates and enforcement. SaaSJet's own monitoring tooling (Amazon CloudWatch, Datadog) covers SaaSJet-operated infrastructure such as our corporate and website services.


Q: What's your business continuity in times of disruption (COVID,etc.)?

A: We work remotely according to the work schedule. Support center available (email and Jira requests) - 24/7, chat service from 12 pm to 8 pm (GMT+3), and phone service from 9 am to 12 am from Monday to Friday.

Our mission is to ensure information system uptime, data integrity, availability, and business continuity. We have process-level plans for recovering critical technology platforms and the telecommunications infrastructure in case of disaster. Learn more


Q: Do developers have access to update the code in production?

A: Only the Lead responsible for the product and the DevOps engineer have access to production for quick response in case of an incident. All code is deployed automatically, and several specialists check each change.


Q: Can we access your Jira instance after cancelling?

A: No, we can`t access your data after canceling, but due to the Atlassian Marketplace Licensing System, you can revoke access within 3 business days.


Q: Information you give us

A: You may give us some personal information with your consent in such cases:

  • By filling in a form or sending us an e-mail;

  • By contacting us via e-mail or some other medium to request service or support (e.g., Jira Service Desk);

  • Applying for a job at SaaSJet.

  • Installing and using our Apps.

When you contact us via email or through Jira Service Desk, we may ask for your name, email address, and any other information you provide. This additional information can include personal, financial, educational, or employment information. We can also ask for specific information to ensure compliance with legal requirements, such as when you place an order or apply for a job with SaaSJet.


Q: Information we collect about you

A: If you visit our website, we automatically collect such information about you:

  • Technical information (configs, save&load information);

  • IP addresses;

  • Information about what type of device you use to connect to our Website or Services; and

  • The manner in which you interact with our services.

Any data or information you enter into any forms on our services is only used for the intended purposes or as it’s described in our Privacy Policy.


Q: Personally identifiable information (PII)

A: We do not transfer or store PII data on our servers. Some of our apps read the user display name from Jira and show it on an work item or App page when

  • list of work items is generated (work item table);

  • data export to CSV or XLS is created;


Q: Who might we share your information with?

A:

  • We may share the collected information about you (including your personal data) for the following reasons: 

  • If it’s required by law.

  • If you indicate this information in our services. In that case, the date and time at which you created, modified, or ran a report will only be shared within the relevant services, including the end user's public display name under which a report has been created or inserted. If you use the app's data-export functionality — the Time in Status REST API — you can share generated report data with other people or third-party analytical systems (e.g., Google Sheets, Power BI). Exports include only the work items the authorized user can view in Jira, and API access uses Atlassian OAuth 2.0.

  • You select filters - We generate a report - You share it with others (if necessary) by using the add-on. 

  • If a third party acquires SaaSJet or essentially all of its assets, your personal data held by SaaSJet will be transferred. 

  • If SaaSJet must comply with any legal obligation.

  • if necessary to protect the rights, property, or safety of SaaSJet, our customers, or others.

Data Residency

Q: Does Time in Status support data residency?

A: Yes. Following the complete migration to Forge and the Runs on Atlassian badge, Time in Status supports Atlassian data residency for in-scope Forge data, so eligible app data can be pinned to the same region as your Atlassian (Jira) data.

More info - Understand data residency | Atlassian Support

App questions

Q: Is it possible to provide permission to selected groups and users?

A: Yes, it is possible. According to the permissions section, if your account has administrator rights, select Permissions in the configuration menu to manage the access for additional users who can update the reports, work schedule, and manage permissions. For more information about this option, read here - Permissions in Time in Status add-on.

If you want to make access at the user level, you can create separate groups for the corresponding users.

Q: Can “Public” presets in the Time in Status app expose information from restricted Jira projects or issues?

A: Yes. If a preset saved as Public contains filters or JQL conditions that reference private or restricted projects, boards, sprints, saved filters, or issues, a technically savvy user without access may still infer sensitive metadata (e.g., private project name, issue key, sprint name, saved filter) by inspecting browser developer tools or network requests. While the interface may mask or substitute parts of this data, saving a preset as Public does not guarantee that Jira access policies will be fully applied in every context. This does not grant access to restricted issue content, but it can reveal the existence of restricted entities and related artifacts.

Do not publish presets that contain conditions or JQL queries referring to private projects, incident boards, sprints, restricted issues, or text searches over summary/description that might hold confidential data (customer names, security incidents, etc.). Use Public presets only for operational reporting and team transparency within open (accessible) projects. Prefer Private or group/role–restricted sharing for any preset that could touch sensitive data. Periodically audit existing Public presets and remove or revise any that reference restricted entities.

Q: Do you have backup and restore of data?

A: Yes, we have backup / restore policy - Documents are available upon the user's request.


Q: Do you have disaster recovery plans?

A: Yes, you can read more here - Documents are available upon the user's request.