# Our applications run inside your Atlassian instance.

Trust and data handling

Every Oktul application is built on Atlassian Forge. Atlassian operates the runtime, stores the data and enforces your permissions, so there is no Oktul-operated server in the path between your users and their work. What follows is the mechanism, and where to check each part of it yourself.

## What Forge is, and why every Oktul application is built on it.

Forge is Atlassian's own application runtime. We build on nothing else, which is what makes the answers below the same for every application we ship rather than a per-product negotiation. They are Atlassian's guarantees rather than ours, and Atlassian's own documentation states every one of them.

- **Runtime:** Atlassian Forge
- **Data storage:** Your Atlassian instance
- **Oktul infrastructure:** None in the data path

1. **The code runs in Atlassian's runtime, on Atlassian's compute** Forge functions execute in Atlassian's own environment, isolated per application, under the scopes the application declares at install. There is no API token, service account or connection string of yours in our custody at any point, no hosting arrangement of ours for you to assess, and no Oktul outage that can affect your apps.
2. **Application data sits in Atlassian storage, and follows your instance** Where an application stores something of its own, it goes in Forge hosted storage, which Atlassian encrypts at rest and scopes to your installation. Data that belongs to a work item stays on the work item. If you move your instance to another residency location, both move with it.
3. **What an application may reach is a list in a file, enforced by a proxy** A Forge app can only reach hosts named in its manifest. Every outbound request passes through an Atlassian proxy that enforces that list at runtime rather than trusting the application to behave. The manifest ships with the application, so you can read the list before you install it, and adding to it forces a fresh approval from your admin.
4. **Runs on Atlassian is Atlassian's verdict, not our claim** Atlassian applies that badge automatically to applications whose manifest shows no egress, Atlassian-hosted storage and matching data residency. We cannot award it to ourselves and cannot opt in. It is granted per application rather than per company.

**Some applications do send data outside Atlassian** Where that is the case, it is documented on that application's page: what leaves, who receives it, what they can do with it, and why the feature cannot work otherwise. The documentation is public, so you can read all of it before you install.

## What reaches us, and the switch that stops it.

This is the one place where something of yours does reach Oktul, so it gets a section rather than a footnote.

When you install a Forge app, Atlassian turns on log sharing automatically and the developer gets access to that application's logs for your site. That is the platform's default rather than a setting we chose, and it applies to every Forge app in your instance, ours included.

We write errors, and nothing else. No work item content, no user records, no measurement of how your team works. Atlassian publishes [logging guidelines](https://developer.atlassian.com/platform/forge/logging-guidelines) that tell developers not to log names, email addresses, usernames or user-generated content, and ours follow them.

You do not have to take that on trust. Download the logs from your own admin console, read exactly what we have been receiving, and then decide whether to keep sharing them.

**Turning log sharing off**

1. Go to admin.atlassian.com and select your organisation.
2. Select Apps, then Sites, then the site you are administering.
3. Select Connected apps, then the application.
4. In the Details tab, turn off Logs access.

The same page downloads the logs before you decide, and your log sharing history is in the audit log. Turning it off costs us the ability to diagnose a fault from our side: we will ask you for the log file instead, which is slower. We would rather say that here than discover it with you during an incident.

## What we commit to, by severity.

An initial response within 24 hours on every request, from the people who wrote the code. The time to a solution depends on what is wrong, so it is written down per severity rather than promised as one number that would be wrong for most of them.

**Initial response, every request** Within 24 hours, Monday to Friday. A request raised outside the working week starts its clock at the beginning of the next one. This applies to every severity below, including the ones that carry no resolution target.

**Working week** Monday to Friday, 09:00 to 17:00, Europe/Tallinn. Resolution targets are in calendar days rather than working days, so a weekend counts against them and the figure means what it says.

| Severity | What it means | Time to solution |
| --- | --- | --- |
| Critical | Production is down, or a technical issue is severely blocking the business. | 7 calendar days |
| Critical security | A vulnerability scoring CVSS 9.0 or above. An immediate threat to cloud infrastructure or to data. | 7 calendar days |
| High security | A vulnerability scoring CVSS 7.0 or above. Significant security exposure with no simple workaround. | 14 calendar days |
| Medium security | A vulnerability scoring CVSS 4.0 to 6.9. A moderate security risk. | 28 calendar days |
| Low security | A vulnerability scoring below CVSS 4.0. A minor security issue with low potential for exploitation. | 56 calendar days |
| Standard support request | A question, a configuration problem, a documentation gap or a feature request. Nothing is broken and nothing is exposed. | No resolution target. The 24-hour response applies as it does to everything else |

The clock runs on a request raised in the Help Center, because that is the only channel where it is measured. Email to support@oktul.com opens a request in the same service desk and carries the same targets. An email to any other address reaches a person rather than a queue, and nothing measures it.

Two limits, stated next to the table rather than discovered later. A security severity is the vulnerability's CVSS score rather than our opinion of it, which is why the scores are printed here; for a technical issue we assign the severity and will explain the assignment if you disagree. And this table covers our response, not the platform's availability: Forge is Atlassian's, our applications have no server of ours in the path, and an uptime figure from us would be a promise about somebody else's infrastructure. Atlassian publishes its own status and targets, which is where availability is answered.

## The documents, and where to check them.

Every claim on this page is either Atlassian's, and checkable in their documentation, or ours, and written down in one of these.

**The company assessment, published rather than described** Oktul is listed in the Cloud Security Alliance STAR Registry at Level 1. That is a self-assessment, not an audit: we completed the CAIQ Lite questionnaire, all 138 questions across the 17 Cloud Controls Matrix domains, and published it for anyone to read. This entry covers the company and carries no application detail. Where an application has been assessed in its own right, that listing is on its own page.

[Read the company assessment on the STAR Registry](https://cloudsecurityalliance.org/star/registry/oktul-llc/services/oktul-llc)

**The documents this rests on**

- [Privacy policy](https://oktul.com/legal/privacy/)
- [Cookie notice](https://oktul.com/legal/cookies/)
- [Website terms](https://oktul.com/legal/terms/)
- [Application licence](https://oktul.com/legal/app-terms/)
- [Data processing addendum](https://oktul.com/legal/dpa/)

**If something goes wrong** We have had no security breach or incident to date. If one occurs, we tell Atlassian within one hour and, where personal data is affected, the Estonian Data Protection Inspectorate within the 72 hours the GDPR allows.

**Reporting a vulnerability** Raise it in the [Help Center]({helpCenter}), or send it to [support@oktul.com](mailto:support@oktul.com) if you would rather write an email. Both open a request in the same service desk, so the report carries a reference and a response target measured against it, and a person who wrote the code reads it. The portal is the better of the two: the routine questions a disclosure starts with, which version, which scope, whether it is already known, are answered there rather than over a week of replies.

## Answered at company level, in full.

Each answer stands on its own if it is pasted into a form, which is where most of these end up.

### Where does our data go when we install an Oktul application?

Data stays inside Atlassian wherever the feature allows, because the applications run on Atlassian Forge inside your own Atlassian instance rather than on infrastructure we operate. Where a feature genuinely requires data to leave, only the minimum leaves, nothing is retained by anyone downstream, and every partner in that path is named on that application’s page. That answer is decided per application, so the page for the application you are evaluating states it in full before you install.

### Who maintains the applications, and what happens if they stop?

Two named solution architects, holding twenty-three Atlassian certifications and accreditations between them, each listed on the company page with the month it was awarded. Oktul OÜ is a registered Estonian company, not an alias. The applications run on Atlassian Forge, which means there is no Oktul-operated server for your instance to depend on: the code runs in Atlassian’s runtime, and your configuration and data remain in your instance whatever happens to us.

### How fast do you respond when something breaks in production?

An initial response within 24 hours, Monday to Friday, on a request raised in our Help Center. Raise it there rather than by email: a request in the portal has a type, a reference and a response target measured against it, and an email has a person reading it and nothing measuring it. The portal is public, needs no account and no Atlassian licence, and asks only for an email address so the reply has somewhere to go. It takes incidents, bugs, questions, demo requests, feature requests and requests for an application we have not built yet, and partners have their own request types. Support is answered by the people who wrote the code, so there is no tier to escalate through before reaching someone who can read the stack trace.

### Why would we trust a small vendor with a production Jira?

Because of where the software runs and what we publish about it, not because of our size. Forge means the application has no server of ours in its path and no credentials of yours in our custody. Every claim we make is checkable: the certifications are listed with dates, the response time is a written SLA, and each application publishes its scopes, storage and egress before you install it. We also state limitations next to the features they bound, which is the part a vendor with something to hide leaves out.

### Is Oktul an Atlassian partner?

Oktul is an Atlassian Marketplace Partner, and we say so at first mention in every material rather than implying a broader relationship. We are not claiming an Atlassian endorsement of any individual application beyond the programme badges Atlassian itself grants, and where an application has been granted one, that badge appears on the application’s own page because it is awarded per application.

### What does it cost to evaluate one?

Pricing, trials and billing all run through the Atlassian Marketplace, on the same terms as every other app in your instance. So the application appears on your existing Atlassian invoice, and it needs no new supplier onboarding, no purchase order and no vendor security review of our payment handling. The documentation is public and needs no trial to read.

- **Senior consultants:** assessed hundreds of applications for clients before we built our own
- **Not our servers:** the applications run inside your own Atlassian instance, on Atlassian’s infrastructure, never on ours
- **Ready to support:** the person who answers your ticket is the one who wrote the code

---

## Published by

- Oktul OÜ (Oktul LLC)
- Oktul OÜ · Reg. nr 17589681 · Tallinn, Harjumaa, Estonia
- Email: hello@oktul.com
- Web: https://oktul.com/
- Atlassian Marketplace: https://marketplace.atlassian.com/vendors/534484195
- Estonian: https://oktul.com/et/
