Version 1.0 · Effective date: 2026-07-17 · Last updated: 2026-07-17
This policy describes the security practices of T&J Małgorzata Ośródka (operating under the brand “VelociBit”) (“we”, “us”, the “Vendor”) for the Blobify – Cloud Attachments for Jira app (the “App”) distributed through the Atlassian Marketplace.
Blobify is a Forge-native app. All App code executes either in Atlassian's Forge runtime or in the end user's browser. There is no third location.
An upload proceeds as follows:
Downloads follow the same pattern in reverse. At no point does the App receive, buffer, proxy, or store file contents.
The App's Forge manifest declares client-side egress only — permitted destinations are the storage providers' own domains. The manifest declares no backend egress permission at all, which means the Forge platform will refuse any outbound network call attempted by the App's backend. This is a platform-enforced guarantee rather than a policy commitment.
Administrators using a self-hosted or arbitrary S3-compatible endpoint (for example MinIO or Ceph) must explicitly register and approve that endpoint for their own installation. The App cannot reach an endpoint that the installation's own administrator has not approved.
Signed URLs are deliberately short-lived, scoped to a single object, and limited to a single operation:
| Operation | Validity |
|---|---|
| Download | 5 minutes |
| Upload | 5 minutes |
| Delete | 5 minutes |
A leaked URL is therefore useful only for a narrow window, against a single object, for a single action.
Blobify does not implement a parallel permission system. Authorization decisions are enforced server-side in the Forge backend on every request:
The App writes diagnostic logs only. Log entries contain Jira issue keys, HTTP status codes, and size counts — they do not contain file contents, filenames, personal data, or credentials. Logs remain within Atlassian's infrastructure and are not transmitted to any third-party logging or monitoring service; as noted in section 3, the backend has no egress permission with which to do so.
Our first line of defence is having less to defend. The App runs on Atlassian Forge and we operate no servers, so there is no host, network, container, or operating system of ours to patch. The App's runtime dependency tree is deliberately small, consisting of Atlassian's own Forge packages, React, and a limited set of well-established open-source libraries; we use no analytics, error-tracking, or telemetry libraries. A small dependency tree means fewer advisories to act on and a smaller supply-chain surface. A software bill of materials is maintained and available on request.
We become aware of vulnerabilities through:
Reported and discovered vulnerabilities are assessed for severity based on exploitability and impact, taking into account the App's architecture — in particular that file contents never reside on systems we control. We aim to remediate according to the internal targets below. These are targets to guide prioritisation, not a contractual service level; actual timelines depend on severity, complexity, and any dependency on the Atlassian platform.
| Severity | Remediation target |
|---|---|
| Critical — exploitable, leading to unauthorised access to customer data or credentials | Within 7 days |
| High — significant impact, or exploitable under realistic conditions | Within 30 days |
| Medium — limited impact or requiring unusual preconditions | Within 90 days |
| Low — minimal practical impact | Next scheduled release |
Every fix passes the same automated checks as any other change (section 9) before release. Because Blobify is a Forge app, a remediated version is deployed by us and propagates to installations without customers needing to take action.
Vulnerabilities in the Atlassian Forge platform itself are Atlassian's to remediate, under the security programme published at atlassian.com/trust. Where a platform advisory requires action on our side — for example an SDK upgrade — we treat it under the same triage process above.
The security of your own cloud storage account — its access policies, network restrictions, encryption settings, and the scope of the credentials you supply to the App — remains yours to manage. We recommend least-privilege, scoped credentials, and rotating them periodically.
The only sub-processor we engage is Atlassian Pty Ltd, as the Forge platform on which the App runs and where App data at rest resides. Atlassian maintains its own certifications and security programme, published at atlassian.com/trust.
The cloud storage provider you configure is your own sub-processor under your agreement with them, not ours. We have no relationship with, contract with, or access to that account beyond the scoped credentials you supply to the App.
We welcome reports from security researchers and customers.
Please report suspected vulnerabilities through our support portal or by email to support@velocibit.io with the subject line SECURITY. Include enough detail to reproduce the issue — affected component, steps, and impact.
We do not currently operate a paid bug bounty programme.
In the event of a security incident affecting the App, we will investigate promptly, take action to contain and remediate, and notify affected site administrators without undue delay, describing what happened, what data was involved, and what steps we and they should take. Where the incident constitutes a personal data breach, we will support the customer (as data controller) in meeting their obligations under Article 33 GDPR, and will notify them without undue delay after becoming aware, consistent with our role as processor.
Because file contents never reside on systems we control, a compromise of the Vendor could not expose your file contents.
We believe in stating our posture plainly rather than implying more than we have. As of the “Last updated” date above:
We will update this section as our security programme develops. If your procurement process requires an assessment we have not listed here, contact us and we will discuss it with you directly.
We may update this Policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, via the Marketplace listing.
Related documents: Privacy Policy · Terms of Use · Data Processing Agreement
T&J Małgorzata Ośródka (brand: VelociBit)
NIP: 7262479786
Jozefow 14B, Jozefow 95-002, Poland
Email: support@velocibit.io