Security
How Renevell protects the information entrusted to its products.
Your data belongs to you
The records you create in our products belong to your organization. We do not sell them, analyse them for our own purposes, or use them for anything other than providing and supporting the product.
EA Sphere for Jira
- EA Sphere is built on Atlassian Forge and designed to Atlassian’s Runs on Atlassian requirements. It runs on Atlassian’s infrastructure rather than on servers operated by Renevell.
- Records are held in Forge storage, which is hosted by Atlassian. The app makes no calls to external services, serves its fonts and assets from within the app, and requires no content security policy exceptions.
- The app requests five scopes:
storage:appto hold its records;read:jira-workandwrite:jira-workto read and update the Jira issues that reference systems;read:jira-userto evaluate users and group membership; andreport:personal-datato take part in Atlassian’s personal data reporting. - Settings and bulk operations require the Administer Jira permission, restricted notices are governed by Jira group membership, and every permission check is enforced on the server.
- EA Sphere does not send email. Notices are prepared in the app and sent by the user from their own email.
Standalone products
Security documentation for the standalone edition of EA Sphere and for Vendor Contracts is provided as part of each proposal, reflecting the configuration agreed with the customer.
Reporting a vulnerability
Please report suspected vulnerabilities to support@renevell.com. Security reports are handled ahead of all other work. We ask for a reasonable opportunity to resolve an issue before it is disclosed publicly, and we will credit reporters who wish to be credited.
Patching and releases
Dependencies are kept current, security fixes are released as soon as they are ready, and every release is documented in the release notes.
Questionnaires
Security questionnaires and procurement enquiries may be sent to support@renevell.com.