Security Incident Response Plan

Applies to the Atlassian Marketplace apps published by Boundless Stream, including Space Access Audit for Confluence and System Field Defaults for Jira.

Version 1.0 · Effective 2026-09-16 · Owner: Boundless Stream (security contact below) · Next review: 2027-09-16

1. Scope and responsibilities

This plan covers security incidents affecting our apps, their build and release pipeline, and any infrastructure we control. Both apps are built and hosted on Atlassian Forge; we do not operate application servers, and we do not store customer data outside Atlassian.

RoleHeld byResponsibility
Incident ownerBoundless Stream security contactOwns detection, triage, remediation, notification and the post-incident review.
Security contactsupport@boundlessstream.comReceives external reports, is registered on ecosystem.atlassian.net, and has access to Atlassian Marketplace Security (AMS) tickets.

2. How we detect incidents

3. Severity and target response times

SeverityExamplesAcknowledgeFix or mitigate
CriticalRemote code execution, exposure of customer data, authentication bypassWithin 1 business dayWithin 5 business days
HighPrivilege escalation, injection reachable by a user, broken authorization on a user-triggered callWithin 2 business daysWithin 10 business days
MediumDenial of service limited to one site, information disclosure with low impactWithin 5 business daysNext scheduled release
LowHardening items, dependency updates with no known exploit pathWithin 10 business daysBacklog, prioritised by risk

Where Atlassian's Marketplace Security Bug Fix policy sets a shorter window for a finding, that window takes precedence.

4. Response procedure

  1. Triage — confirm the report, assign a severity from the table above, and open a private record.
  2. Contain — if the issue is exploitable in production, ship the smallest safe mitigation first (for example, disabling an affected code path), then fix the root cause.
  3. Remediate — fix on a branch, add a regression test, run the full test suite and dependency scan, then deploy to the development environment and verify before production.
  4. Verify — reproduce the original issue against the fixed version, and confirm the fix from Atlassian's scanning where applicable.
  5. Notify — see section 5.
  6. Review — within 10 business days of closing, record what happened, the root cause, what detection or process change prevents a repeat, and update this plan if needed.

5. Notification commitments

6. Records and review

For every incident we keep an internal record: date, severity, description, affected versions, root cause, remediation, timeline of the customer and Atlassian notifications, and the follow-up actions. This plan is reviewed at least annually, and after any Critical or High severity incident.

Report a security issue
Email support@boundlessstream.com. If you prefer to report through Atlassian, findings raised in the Marketplace Security (AMS) project for our app keys reach us directly.