Partner Security Policy
Overview
Come2Solution provides various apps, which are available on the Atlassian marketplace. All apps are Cloud apps based on the Atlassian Cloud platform, specifically built on the Atlassian Forge Platform. We follow Atlassian’s security policies to protect user configurations and do not save any personal information or data through the apps unless explicitly required for support or licensing.
Data Security & Controls
We use organizational, technical and administrative measures to protect any information that passes through our systems. Access to your information is limited to those who have a proper business need to access it, and those individuals will do so only in an authorized manner and subject to a duty of confidentiality.
Infrastructure: Our Cloud services are hosted in Amazon Web Services (AWS) data centers. AWS holds numerous security certifications (e.g., ISO 27001, SOC). For more information, refer to AWS Security and AWS Compliance.
Data in Transit: Where data is transferred over the Internet as part of our Website or Cloud services, it is transmitted using industry standard HTTPS using TLS.
Data at Rest: For any data stored in our supporting systems (e.g., Jira Service Management for support tickets), we rely on AWS and Atlassian’s encryption standards for data at rest.
Access Control: Within Come2Solution, access to production environments and customer support data is granted only to specific team members on a need-to-know basis and is monitored for unusual activity.
Third-Party Security: Because our apps run on the Atlassian Forge platform, we adhere to the Atlassian Cloud Security Program requirements.
Security Program, Vulnerability Management & Incident Response
Protecting your data is critical to Come2Solution. We maintain a proactive security program that includes the following:
Vulnerability Management: We regularly review our apps and supporting infrastructure for known security vulnerabilities. When updates are required, we apply patches in a timely manner following testing. We also monitor security advisories from Atlassian and AWS.
Issue Handling: If a potential security issue is reported to us (e.g., via email to
info@come2solution.com), we will acknowledge the report within 3 business days and work to investigate and validate the issue.Incident Response: In the unlikely event of a security incident or data breach that affects customer data, Come2Solution will:
Immediately contain the incident.
Investigate the root cause.
Notify affected customers and Atlassian without undue delay (typically within 72 hours of confirmation) in accordance with applicable laws and Marketplace requirements.
Contact for Security Issues: Please report any suspected security vulnerabilities or incidents to
info@come2solution.com. For sensitive reports, please use “Security Issue” in the subject line.
Important Acknowledgment: Unfortunately, no data transmission or storage system can be guaranteed 100% secure. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of any account you might have with us has been compromised), please immediately notify us using the contact above.
End of subscription
If a customer unsubscribes from one of our Cloud apps, we will delete any personal data after three months (or earlier) – unless a longer retention period is legally required. Please contact info@come2solution.com for immediate deletion if you wish.
Data location
All our apps are built with Atlassian Forge and hosted on Atlassian Cloud. No customer data is replicated to separate Come2Solution-controlled data centers.