Cloud Scheduler
HomePulseResourceScheduleCalendarGanttTimesheetPricingDocsSecurityContact
ContactReviewer guide

Security

Last updated: July 1, 2026

Cloud Scheduler is designed as a Forge-native Jira Cloud app. This page is intentionally detailed for customers, procurement teams and Atlassian Marketplace review.

Executive summary

  • Built for Jira Cloud and presented as an Atlassian Forge app.
  • Normal operation does not require a vendor-hosted external backend.
  • Application data is intended to be stored in Forge Storage.
  • Authentication is handled by Atlassian; authorization follows Jira permissions and Forge scopes.
  • The app does not intentionally collect Atlassian passwords, login sessions, card data or authentication secrets.

Authentication and authorization

  • Cloud Scheduler relies on Atlassian authentication context.
  • Access to Jira data is governed by Jira permissions and scopes granted at installation.
  • The app does not access Atlassian login credentials or sessions.
  • The app does not modify Atlassian identity properties or user passwords.

Scopes

  • read:jira-work
  • write:jira-work
  • read:jira-user
  • storage:app

Security controls

  • Least-privilege scope review before release.
  • No API keys or secrets in client-side code.
  • Input validation and output encoding for user-provided values.
  • No intentional collection of passwords, payment card data or authentication secrets.
  • Security reports accepted at support@cloudschedulerapp.com.

Vulnerability management

  1. Receive report through support or security email.
  2. Acknowledge within the support target.
  3. Classify severity and customer impact.
  4. Fix, test and deploy remediation.
  5. Update documentation or customers if required.
Cloud Scheduler

support@cloudschedulerapp.com

DocsSupport & SLAPrivacySecurityData handlingTrust centerIncident responseTermsEULAFAQMarketplace checklist
Zoomed screenshot