Security Policy
This policy explains how Recall (“Recall”, “we”, “us”) secures data accessed from your Jira Cloud site. It complements our Privacy Policy, which covers what data we collect and why; this page focuses on how that data is protected in transit, at rest, and operationally.
1. Core security principles
Recall is built around a small set of principles that shape every design decision:
- Least privilege — only the Jira data required for the feature is accessed.
- Project scoping — only projects an administrator explicitly enables are processed.
- Data minimization — only data necessary for functionality is stored.
- Tenant isolation — customer data is logically isolated per Jira site.
- Resilience — failures in external services do not disrupt core functionality.
2. Encryption
- Data in transit is encrypted using HTTPS/TLS.
- Data at rest, including OAuth access and refresh tokens, is protected using industry-standard encryption.
- Secrets and credentials are stored securely and rotated as needed.
3. Access control
- Administrative actions (enabling projects, configuration) are restricted to Jira administrators.
- Recall does not introduce new user roles or permission structures.
- Existing Jira permissions continue to govern issue visibility — users only ever see suggestions for issues they already have access to in Jira.
4. Data isolation and minimization
- Customer data is logically isolated by tenant; no customer data is shared across tenants.
- Large issue descriptions may be truncated before processing.
- We do not access attachments, credentials, or Jira configuration data.
5. Data retention and deletion
- Indexed data is retained only while a project remains enabled.
- If a project is disabled, its indexed data is scheduled for removal.
- If Recall is uninstalled, all indexed data for the tenant is deleted within 24 hours.
6. Monitoring and auditing
We maintain internal logs and metrics for system health, performance, and error detection. Logs are used solely for operational purposes and are never exposed to other customers.
7. Incident response
In the event of a security or availability incident, we:
- Assess impact promptly upon detection.
- Apply mitigations to restore normal operation as quickly as possible.
- Notify affected customers when appropriate, in line with Atlassian Marketplace expectations.
8. Vulnerability management
Dependencies and infrastructure are kept up to date, and known vulnerabilities affecting the service are remediated on a priority basis. If you believe you've found a security vulnerability in Recall, please report it to the address below — we will investigate promptly.
9. Subprocessors
Recall uses a small number of third-party service providers for narrow processing purposes (semantic search embeddings and relevance re-ranking), as described in our Privacy Policy. These providers do not train their general-purpose models on your data, and your data is never sold or exposed to any other party.
10. Compliance posture
Recall is designed to align with common enterprise security expectations, including secure development practices, least-privilege access, and data isolation and minimization. Formal certifications (e.g. SOC 2, ISO 27001) may be pursued as the product matures.
11. Contact
Questions about this policy, or reports of a suspected security issue, can be sent to our security team.
Last updated: July 31, 2026