Kifas Security
Last Updated: 12 September 2026
Kifas uses administrative and technical controls to protect customer data throughout its lifecycle. This page describes the controls currently in place. Report a security concern to security@kifas.io.
Data protection
- Network traffic to Kifas services is encrypted with TLS 1.2 or newer.
- Customer data stored outside Atlassian is encrypted at rest with AES-256 or an equivalent provider-managed control.
- Production access is limited by role and protected with multi-factor authentication.
- Secrets and credentials are kept outside source control and are available only to the services and people that need them.
- Customer organizations are separated by tenant authorization controls, including row-level security in the Kifas database.
The Privacy Policy describes the data Kifas collects, why it is used, and how long it is retained. The Subprocessors page lists service providers and processing locations.
Application and infrastructure security
Kifas reviews code changes before release and uses automated dependency and static analysis checks. Production services use least-privilege access, request validation, parameterized database access, output escaping, logging, monitoring, and vulnerability and patch management. Kifas for Jira logs contain limited technical identifiers such as installation IDs, Jira issue keys, and job IDs. They exclude ticket titles, descriptions, comment bodies, Atlassian account IDs, email addresses, Forge tokens, passwords, and API keys.
Kifas maintains an incident-response process for investigating, containing, remediating, and communicating security incidents. Customers and relevant authorities are notified when required by law or contract.
Kifas for Jira
Kifas for Jira is an Atlassian Forge app with one declared remote, api.kifas.io. It does not store data in Forge storage. All egress from the Forge runtime goes to that declared remote. When a customer uses an AI-enabled Kifas feature, the Kifas service may send the relevant Jira content to the configured model provider under the controls described in the Privacy Policy. Current providers and processing locations are listed on the Subprocessors page.
The Kifas remote validates Forge Invocation Tokens before accepting Forge requests. User-facing requests use short-lived user context and verify the person's Jira permissions before protected Jira data or administrative controls are returned. App credentials are short-lived, encrypted with AWS KMS envelope encryption, replaced when refreshed, and never written to logs, URLs, or source code.
The app requests only the Jira scopes needed for issue synchronization, permission checks, customer-directed Jira writes, and Atlassian personal-data lifecycle reporting. Its Jira data handling and deletion behavior are documented in the Kifas for Jira section of the Privacy Policy.
Kifas follows Atlassian's Marketplace Security Bug Fix Policy for Kifas for Jira. Dependency and static analysis results are reviewed before release, and security fixes are prioritized according to severity.
Data deletion
When a Jira site is unlinked or Kifas for Jira is uninstalled, access stops immediately and app credentials are deleted. Retained Jira data and data derived from it are permanently purged within 30 days. Kifas also participates in Atlassian's personal-data reporting cycle and erases stored personal data for accounts Atlassian reports as closed.
Certifications
Kifas does not currently claim SOC 2, ISO 27001, FedRAMP, HIPAA, or other independent security certification for the service. Customers should rely on the controls and disclosures published here rather than an implied certification.
Report a vulnerability
Email security@kifas.io with the affected service, a description of the issue, reproduction steps, and its potential impact. Do not include live customer data or publicly disclose an unresolved issue. Kifas will review the report, coordinate remediation, and communicate with affected customers and Atlassian when required.