BlueGrove Labs markBlueGrove Labs
Trust

Trust & Security

StatusPath Reports is built on Atlassian Forge for Jira Cloud teams, with report access designed around Jira permissions and customer data boundaries.

Forge-built

Built on Atlassian Forge and designed to align with Forge app infrastructure, authentication, tenant isolation, and egress controls.

Jira permissions

Reports use Atlassian and Jira APIs within the permissions granted to the app and the current Jira user.

Minimal storage

StatusPath stores report setup and product settings, not permanent snapshots of generated report rows or downloaded exports.

Built on Atlassian Forge

StatusPath Reports - Time in Status for Jira is a Jira Cloud Forge app from BlueGrove Labs.

Forge provides Atlassian-hosted app infrastructure, built-in authentication, tenant isolation, and controlled data egress mechanisms. StatusPath Reports is designed to align with Atlassian Forge's security model rather than treating security as a separate backend layer.

Atlassian Forge overviewForge platform overview and secure-by-design model.Forge shared responsibility modelHow Atlassian and app vendors share responsibilities for Forge apps.

Jira permissions are respected

StatusPath Reports uses Atlassian and Jira APIs only within the permissions granted to the app and the current user.

Jira permissions are not bypassed by app scopes. Users can only report on work items they are allowed to view in Jira.

Forge permissionsForge manifest permissions, scopes, and external permissions.Jira scopes and Jira permissionsAtlassian notes that Jira permissions still control data access and are not overridden by scopes.

Minimal data access

StatusPath Reports reads Jira data needed to calculate Time in Status, Average Time in Status, Time in Assignee, Status Count, Status Entry Date, Transition Count, charts, saved report setup, dashboard gadget views, and exports.

  • Work item key, summary, status, assignee, project, issue type, created, updated, and resolved dates
  • Changelog history needed for status, assignee, and time calculations
  • Selected Jira fields included in reports
  • Project, filter, JQL, board, sprint, epic, status, user, and field metadata used by setup controls

What StatusPath stores

StatusPath stores configuration data that helps users restore and personalize reporting workflows.

Stored configuration

  • Saved report configurations
  • Default report settings
  • Recent setup and user preferences
  • Business calendar settings
  • Dashboard gadget configuration
  • Admin and project settings required by product features

Not stored as permanent snapshots

  • We do not intentionally store generated report result rows as permanent snapshots.
  • We do not store downloaded CSV/XLSX export files.
  • We do not publish customer Jira data in public documentation.
  • We do not use customer report data for marketing examples.

Forge storage and data residency

Configuration data may be stored in Atlassian Forge Storage or Jira app, dashboard, and entity properties, depending on the product feature.

Forge persistent storage supports Atlassian data residency capabilities, and Atlassian documentation describes Forge storage as scoped so an app cannot read stored data from different sites, Atlassian apps, or app environments.

BlueGrove Labs does not promise a specific data residency region on this page unless that region is confirmed in Atlassian or Marketplace configuration.

Forge data residencyAtlassian documentation for data residency support in Forge.Forge key-value storeForge hosted storage, data residency inheritance, and storage isolation details.

External data egress

The current Forge manifest for StatusPath Reports was checked for permissions.external, remotes, providers, and webtrigger entries. No external egress, remote services, providers, or web triggers were declared.

Current report calculations primarily run in the frontend within the Jira Cloud app context.

StatusPath Reports does not use a BlueGrove Labs-hosted reporting backend for Jira report data. Customer Jira report data is not sent to BlueGrove Labs servers for report processing.

Runtime egress permissionsHow Forge apps declare external domains for runtime egress.

Runs on Atlassian readiness

The Forge CLI production eligibility check reported the deployed app version as eligible for the Runs on Atlassian program.

This app is designed to align with Runs on Atlassian requirements. We only describe StatusPath Reports as a Runs on Atlassian app where Atlassian Marketplace shows the official badge.

Runs on AtlassianAtlassian program overview and eligibility context.Forge eligibility commandForge CLI command for checking Runs on Atlassian eligibility.

Support data

Support requests may include report settings, screenshots, error messages, Jira site context, and anonymized examples that customers choose to send.

Do not include secrets, tokens, private Jira URLs, or customer-sensitive screenshots unless your organization has approved sharing that information with support.

Open support portalEmail support@bluegrovelabs.com

Security contact

For security questions or suspected issues, contact support@bluegrovelabs.com. Please include the product name, Jira site URL when relevant, impact, steps to reproduce, and any safe screenshots or error messages.

Contact BlueGrove Labs

Security issues and privacy requests can be sent to support@bluegrovelabs.com. Product support should use the support portal when available.

Email support@bluegrovelabs.comSupport portal

Related policies

BlueGrove Labs public website may use hosting, DNS, security, and lightweight analytics services. These website services are separate from the Jira app report processing.

Review the Privacy Policy, Terms, and Support pages for more information about website and app usage.

Privacy PolicyData access, storage, sharing, retention, and customer choices.TermsGeneral terms for using the website and StatusPath Reports.SupportSupport channels and what to include in a request.
Questions?support@bluegrovelabs.com

These pages are written for public product information and do not include customer-specific data.

Open StatusPath Reports documentation