Security
How we protect your data, and what to do if you find a security problem in one of our products.
Report a vulnerability
Email support@iiclabs.com with "Security" at the start of the subject. Include the product, the steps to reproduce and the impact you expect. Please don't access other people's data, disrupt the service or make the problem public before it is fixed. We confirm receipt within two business days and keep you informed until the problem is fixed.
For Field Defaults & Create Rules for Jira we follow the Atlassian Marketplace Security Bug Fix Policy and its fix timeframes, and we aim for the same timeframes in our other products.
Security incidents
If a security incident affects customer data, we contain it, investigate it, and notify the affected customers and the marketplace involved (Atlassian, Shopify, Google or Apify) without undue delay, and within the time the law requires (72 hours for personal data under the GDPR).
How we work
- Each product asks for the fewest permissions it needs to work.
- Production dependencies are scanned for known vulnerabilities every week, and updates are proposed automatically.
- Secrets such as API keys live only on our server, never in source code or in the browser extension.
- All traffic uses HTTPS. Our server accepts SSH keys only (no passwords), runs a firewall, installs security updates automatically and is backed up daily.
- Logs never contain passwords, API keys or licence keys.
Data by product
- Field Defaults & Create Rules for Jira runs entirely on Atlassian's platform (Runs on Atlassian). Its rules are stored in Atlassian's Forge storage, in your site's data-residency location, and it has no access to external networks.
- Accessibility Auditor audits pages in your browser; page content is never sent anywhere. Only a licence key you enter is checked with our server and our payment provider Creem.
- Linesmith Line Sheets reads products and inventory only (no customer or order data). Generated files are deleted after 30 days, and everything is deleted 48 hours after you uninstall the app.
- Career-Site Jobs API runs in your own Apify account and collects only public job postings from companies' job boards.
More detail is in the privacy policy.