No external data processing
All app logic runs inside Atlassian's cloud. We don't operate infrastructure, so there's nothing to audit beyond the app manifest.
Minimal scopes
We request only the permissions we need. Notably absent: write:jira-work. Our apps read issue data to render panels and checklists — they don't modify your issues.
Data residency
Your data is stored in Forge Storage, which inherits your Atlassian data residency settings. If your Jira data lives in the EU, so does your NovaCraft Tools data.
Vendor consolidation
Three tools, one vendor. One security review covers all three apps. One procurement process. One vendor to manage. That matters when you're managing 40+ Marketplace apps.
US-based vendor
NovaCraft Tools is a US-based company. US legal jurisdiction for contract disputes and data subject requests, US business hours for support, and a familiar W-9 / 1099 trail for procurement. Most established competitors in this space are based in the UK, Iceland, or EU.
Security questionnaire support
We respond to vendor security questionnaires (CAIQ, SIG, custom) within 5 business days. The Trust & Security page already answers most of what your security team will ask — scope, data handling, encryption, compliance posture.