Security Policy

At resolution Reichert Network Solutions GmbH (“resolution”), protecting the data our customers trust us with is a core part of how we build and operate our Atlassian Marketplace apps. This page summarizes the security practices, controls, and commitments that apply across our products and infrastructure.

1. Compliance

Our organization undergoes an annual independent SOC 2 Type II audit. You can find the report in our Trust Center. All of our Atlassian Marketplace Cloud apps are part of Atlassian’s Cloud Fortified Apps Program, including full completion of Atlassian’s Privacy & Security tab and participation in Atlassian’s Marketplace Security Bug Bounty Program. The latter also applies to our Data Center apps.

2. Vulnerability Disclosure & Bug Bounty

We have operated a continuous, researcher-driven security testing program via Bugcrowd since 2019, covering all production systems including our Atlassian Marketplace apps. Security researchers can report findings through our Bugcrowd-hosted bug bounty program.

3. Data Protection & Encryption

All data is encrypted in transit using TLS 1.2 or higher. All data is encrypted at rest via provider-managed encryption keys for underlying storage volumes and databases. Sensitive data is additionally encrypted at rest at the application level.

We classify data according to sensitivity and apply corresponding handling requirements. Customer data is used exclusively to provide our services and is not used for development, testing, or AI model training. Upon termination of a customer relationship, customer data is deleted in line with our data retention procedures.

Our sub-processors – third parties that process customer data on our behalf, such as our cloud hosting and database providers – are listed with their purpose, description and processing location in our Trust Center, which is the authoritative and continuously maintained record (also referenced by our Data Processing Addendum).

4. Infrastructure & Application Security

Our cloud applications run on established cloud infrastructure providers, using containerized, auto-scaling deployments with network segmentation between public-facing and internal components. Web-facing services enforce HSTS, a content security policy, and automatic HTTP-to-HTTPS redirection.

Our development process requires mandatory peer review before any production deployment, automated static analysis and dependency vulnerability scanning on every build, and a separate, gated pipeline for staging and production releases. Vulnerabilities identified through automated scanning, our bug bounty program, or vendor advisories are risk-assessed and remediated according to the timelines set by Atlassian for Marketplace apps.

5. Access Control

Access to production systems and customer data follows the principle of least privilege and is restricted to authorized personnel. SSO and/or Multi-factor authentication is required for all systems that provide access to company or customer data, and access rights are reviewed on a regular basis.

6. Business Continuity & Disaster Recovery

We maintain documented business continuity and disaster recovery plans covering both our ownoperations and the infrastructure underlying our apps. Production data is backed up on an hourly ordaily basis depending on the system, stored separately from the primary production environment, and recovery procedures are tested at least annually. Our target recovery objectives for customer-facing cloud services are a recovery time objective (RTO) of 24 hours and a recovery point objective (RPO) of 1 hour.

7. Incident Response & Customer Notification

We maintain a documented incident response process covering detection, escalation, containment, and remediation of security incidents. Should we become aware of an incident affecting customer data, we will notify affected customers without undue delay and in line with our contractual and legal obligations, through agreed customer contact channels and our status page.

8. Employee Security

All personnel receive security awareness training as part of onboarding and on an ongoing basis. Company-managed devices are required to use full-disk encryption, automatic screen locking, and up-to-date security patches. Access to company and customer systems is revoked promptly when an employee’s role ends.

9. Third-Party & Vendor Management

We assess the security posture of vendors and sub-processors before onboarding and periodically thereafter, and maintain data processing agreements with all parties that process personal data on our behalf.

10. Contact

Questions about this policy or about our security practices generally can be directed to atlassianplugins@resolution.de. Suspected vulnerabilities should be reported through our bugbounty program or the same address.

11. Changes to this Policy

We may update this policy from time to time to reflect changes in our practices, technology, or legal requirements.