Security and Vulnerability Disclosure
If you believe you have found a vulnerability in a Simplify product or website, email [email protected] with the subject Security report. Reports about Secret Sentinel should identify whether the Jira app, Confluence app, or both are affected.
What to include
- the affected product and Marketplace URL;
- the behavior you observed and the security impact;
- reproducible steps using a test site and synthetic data;
- relevant version, browser, and Atlassian product details;
- a minimal proof of concept, if one is safe to share;
- a contact address for follow-up.
Do not send live credentials, authentication cookies, private keys, or customer content. Replace them with synthetic values and redact unrelated personal information. If sensitive material is essential to validate the report, first ask us to agree on a safe transfer method.
How we handle reports
We aim to acknowledge a security report within two business days, reproduce and triage it, and keep the reporter informed at meaningful milestones. Fix timing depends on severity, exploitability, and whether remediation requires Atlassian platform action. This is a response target, not a contractual service-level agreement.
Please make a good-faith effort to avoid privacy violations, service disruption, data destruction, social engineering, and access beyond what is necessary to demonstrate the issue. Allow a reasonable remediation period before public disclosure. We will not pursue action against good-faith research that follows these guidelines, but this policy cannot authorize testing of third-party systems or override applicable law or Atlassian’s terms.
There is currently no public paid bug-bounty program, and submission does not create an entitlement to payment. We do credit helpful reporters when requested and appropriate.
For product architecture and data handling, see the Secret Sentinel Trust Center.