Trust
Security
Fabric Link mirrors Jira into your Fabric tenant. Data leaves Jira read-only; writes go only to Microsoft endpoints you authorize.
Data flow
Jira → Forge → Fabric. Read-only from Jira; writes only to your Fabric tenant.
What we read
- Jira issues, field values, and changelog history for in-scope projects.
- Project and field metadata required to map columns.
- Jira Service Management SLA, request-type, and approval data when JSM mirroring is enabled.
- Display names and account IDs for users referenced on issues (assignee, reporter, change authors).
What we never store
- Issue content on vendor-operated servers outside Atlassian Forge scoped storage.
- Your Entra client secret in plaintext outside Forge encrypted secret storage.
- Exported rows in any destination other than the Fabric workspace you configure.
TODO: Legal/security to confirm final data inventory for Marketplace submission.
Authentication & consent
- Jira access uses Forge app scopes granted at install time — read-only for work data.
- Fabric writes use a customer-owned Entra service principal you provision and rotate.
- Admin consent for the service principal is performed in your Entra tenant, not by Fabric Link.
TODO: Confirm final scope list matches Forge manifest before publish.
Hosting & data residency
- The Forge runtime executes in Atlassian Cloud, scoped to your Jira site installation.
- Mirrored data lands in your Fabric workspace, in the region your Microsoft tenant administrator selected.
- Operational state (queues, watermarks, configuration) lives in Forge storage until uninstall.
TODO: Atlassian + Microsoft docs to cite for residency statements.
Tenancy isolation
- Each Jira site installation is isolated — no shared database between customers.
- Fabric workspace access is limited to the service principal credentials you supply.
- Egress from the app is restricted to Microsoft endpoints required for mirroring.
Encryption
- In transit: TLS for all Jira API, Entra token, Fabric API, and OneLake calls.
- At rest: Fabric and OneLake encryption is governed by Microsoft’s platform controls.
- Secrets: Entra client secrets stored in Forge encrypted secret storage.
TODO: Security team to confirm cipher suites and key management claims if required by procurement.
Subprocessors
- Atlassian Forge — app runtime and scoped storage.
- Microsoft Azure / Fabric — destination for mirrored data you authorize.
TODO: Publish subprocessor list with legal entity names and regions before enterprise sales.
Incident contact
- Report a suspected security issue: TODO: security@fabriclink.dev (confirm mailbox before launch).
- Include your Jira site URL, installation ID, and a description of the concern.
- We will acknowledge within TODO: N business days (confirm response target).
Further reading
- Marketplace security self-assessment — Link once Marketplace listing is live.
- Privacy policy
- Permissions & consent (docs)
Questions for procurement? Email support@haydongroup.com with your security questionnaire.