fabriclink

Trust

Security

Fabric Link mirrors Jira into your Fabric tenant. Data leaves Jira read-only; writes go only to Microsoft endpoints you authorize.

Data flow

Data flows from Jira on the left through the Forge app to mirrored tables in Microsoft Fabric on the right. Nothing is written back to Jira.

Jira → Forge → Fabric. Read-only from Jira; writes only to your Fabric tenant.

What we read

  • Jira issues, field values, and changelog history for in-scope projects.
  • Project and field metadata required to map columns.
  • Jira Service Management SLA, request-type, and approval data when JSM mirroring is enabled.
  • Display names and account IDs for users referenced on issues (assignee, reporter, change authors).

What we never store

  • Issue content on vendor-operated servers outside Atlassian Forge scoped storage.
  • Your Entra client secret in plaintext outside Forge encrypted secret storage.
  • Exported rows in any destination other than the Fabric workspace you configure.

TODO: Legal/security to confirm final data inventory for Marketplace submission.

Authentication & consent

  • Jira access uses Forge app scopes granted at install time — read-only for work data.
  • Fabric writes use a customer-owned Entra service principal you provision and rotate.
  • Admin consent for the service principal is performed in your Entra tenant, not by Fabric Link.

TODO: Confirm final scope list matches Forge manifest before publish.

Hosting & data residency

  • The Forge runtime executes in Atlassian Cloud, scoped to your Jira site installation.
  • Mirrored data lands in your Fabric workspace, in the region your Microsoft tenant administrator selected.
  • Operational state (queues, watermarks, configuration) lives in Forge storage until uninstall.

TODO: Atlassian + Microsoft docs to cite for residency statements.

Tenancy isolation

  • Each Jira site installation is isolated — no shared database between customers.
  • Fabric workspace access is limited to the service principal credentials you supply.
  • Egress from the app is restricted to Microsoft endpoints required for mirroring.

Encryption

  • In transit: TLS for all Jira API, Entra token, Fabric API, and OneLake calls.
  • At rest: Fabric and OneLake encryption is governed by Microsoft’s platform controls.
  • Secrets: Entra client secrets stored in Forge encrypted secret storage.

TODO: Security team to confirm cipher suites and key management claims if required by procurement.

Subprocessors

  • Atlassian Forge — app runtime and scoped storage.
  • Microsoft Azure / Fabric — destination for mirrored data you authorize.

TODO: Publish subprocessor list with legal entity names and regions before enterprise sales.

Incident contact

  • Report a suspected security issue: TODO: security@fabriclink.dev (confirm mailbox before launch).
  • Include your Jira site URL, installation ID, and a description of the concern.
  • We will acknowledge within TODO: N business days (confirm response target).

Further reading

Questions for procurement? Email support@haydongroup.com with your security questionnaire.