LogMyTime — Security Policy

Publisher: LogMyTime, by Bazoho · Contact: support@bazoho.com · Last updated: 2026-08-25

LogMyTime is built 100% on Atlassian Forge: Atlassian-hosted compute (sandboxed Node.js), Atlassian-hosted storage (Forge SQL), and Atlassian-managed identity. Bazoho operates no servers, domains, or databases of its own, and the app declares no external egress — the Forge platform blocks any undeclared network call at runtime.

Platform

Authorization model

Authorization is enforced server-side in every resolver:

Application security

Data protection

Vulnerability management

Incident response

We maintain a written incident response plan aligned with Atlassian’s Marketplace incident-management guidelines. Because the app has no vendor-operated infrastructure, the relevant incident classes are a defect in the app’s own code, compromise of a developer account, or a platform incident on Atlassian’s side. Our process:

  1. Acknowledge reports within 2 business days.
  2. Triage and contain — reproduce and severity-rate the issue; because Forge deployment is immediate, containment normally means deploying a fix or disabling the affected feature. Suspected account compromise triggers credential rotation, session revocation, and a deploy-history audit.
  3. Assess impact using the app’s audit trail and Forge invocation logs; since data never leaves Atlassian, exposure analysis is scoped to what the flaw allowed within an affected site.
  4. Notify — if customer data was or may have been affected, or a critical vulnerability existed, we notify Atlassian and affected customers without undue delay, using Atlassian’s vulnerability-notification format.
  5. Learn — every incident ends with a retrospective and any resulting changes to our practices and this policy.

Vendor operational security

Known trade-offs and disclosures

Vulnerability reporting

Report security issues to support@bazoho.com. We aim to acknowledge reports within 2 business days. Please include reproduction steps, and do not test against Jira sites you do not control.