Trust & Security
StatusPath Reports is built on Atlassian Forge for Jira Cloud teams, with report access designed around Jira permissions and customer data boundaries.
Forge-built
Built on Atlassian Forge and designed to align with Forge app infrastructure, authentication, tenant isolation, and egress controls.
Jira permissions
Reports use Atlassian and Jira APIs within the permissions granted to the app and the current Jira user.
Minimal storage
StatusPath stores report setup and product settings, not permanent snapshots of generated report rows or downloaded exports.
Built on Atlassian Forge
StatusPath Reports - Time in Status for Jira is a Jira Cloud Forge app from BlueGrove Labs.
Forge provides Atlassian-hosted app infrastructure, built-in authentication, tenant isolation, and controlled data egress mechanisms. StatusPath Reports is designed to align with Atlassian Forge's security model rather than treating security as a separate backend layer.
Jira permissions are respected
StatusPath Reports uses Atlassian and Jira APIs only within the permissions granted to the app and the current user.
Jira permissions are not bypassed by app scopes. Users can only report on work items they are allowed to view in Jira.
Minimal data access
StatusPath Reports reads Jira data needed to calculate Time in Status, Average Time in Status, Time in Assignee, Status Count, Status Entry Date, Transition Count, charts, saved report setup, dashboard gadget views, and exports.
- Work item key, summary, status, assignee, project, issue type, created, updated, and resolved dates
- Changelog history needed for status, assignee, and time calculations
- Selected Jira fields included in reports
- Project, filter, JQL, board, sprint, epic, status, user, and field metadata used by setup controls
What StatusPath stores
StatusPath stores configuration data that helps users restore and personalize reporting workflows.
Stored configuration
- Saved report configurations
- Default report settings
- Recent setup and user preferences
- Business calendar settings
- Dashboard gadget configuration
- Admin and project settings required by product features
Not stored as permanent snapshots
- We do not intentionally store generated report result rows as permanent snapshots.
- We do not store downloaded CSV/XLSX export files.
- We do not publish customer Jira data in public documentation.
- We do not use customer report data for marketing examples.
Forge storage and data residency
Configuration data may be stored in Atlassian Forge Storage or Jira app, dashboard, and entity properties, depending on the product feature.
Forge persistent storage supports Atlassian data residency capabilities, and Atlassian documentation describes Forge storage as scoped so an app cannot read stored data from different sites, Atlassian apps, or app environments.
BlueGrove Labs does not promise a specific data residency region on this page unless that region is confirmed in Atlassian or Marketplace configuration.
External data egress
The current Forge manifest for StatusPath Reports was checked for permissions.external, remotes, providers, and webtrigger entries. No external egress, remote services, providers, or web triggers were declared.
Current report calculations primarily run in the frontend within the Jira Cloud app context.
StatusPath Reports does not use a BlueGrove Labs-hosted reporting backend for Jira report data. Customer Jira report data is not sent to BlueGrove Labs servers for report processing.
Runs on Atlassian readiness
The Forge CLI production eligibility check reported the deployed app version as eligible for the Runs on Atlassian program.
This app is designed to align with Runs on Atlassian requirements. We only describe StatusPath Reports as a Runs on Atlassian app where Atlassian Marketplace shows the official badge.
Support data
Support requests may include report settings, screenshots, error messages, Jira site context, and anonymized examples that customers choose to send.
Do not include secrets, tokens, private Jira URLs, or customer-sensitive screenshots unless your organization has approved sharing that information with support.
Security contact
For security questions or suspected issues, contact support@bluegrovelabs.com. Please include the product name, Jira site URL when relevant, impact, steps to reproduce, and any safe screenshots or error messages.
Contact BlueGrove Labs
Security issues and privacy requests can be sent to support@bluegrovelabs.com. Product support should use the support portal when available.
Related policies
BlueGrove Labs public website may use hosting, DNS, security, and lightweight analytics services. These website services are separate from the Jira app report processing.
Review the Privacy Policy, Terms, and Support pages for more information about website and app usage.