Greenlight

Trust Center

Last updated: 24 July 2026

The Trust Center for Greenlight — Release Readiness & Approvals ("the app"), published by Sanyasha Software for Jira Cloud on the Atlassian Marketplace. It brings our security, privacy, and compliance posture together in one place so you can evaluate the app before you install it.

At a glance

  • Runs on Atlassian. The app is built entirely on Atlassian Forge. All code executes on Atlassian-operated infrastructure and all data is stored in Forge SQL, tied to your own Atlassian site.
  • Zero egress. No external servers, no third-party services, no remote APIs, no telemetry. No data ever leaves Atlassian's infrastructure — this is technically enforced by the platform, not just promised.
  • No vendor access to your data. Sanyasha Software operates no infrastructure that could receive customer data and holds no credentials, tokens, or API keys for the app.
  • Least privilege. The app requests three read/storage scopes only, never writes to your Jira issues, workflows, or versions, and runs as the acting user so Jira's own permission model always applies.

Security

Greenlight inherits Atlassian's platform security controls — sandboxed runtime isolation, encryption in transit and at rest, and per-site data partitioning — because it runs entirely inside Forge. Access is enforced server-side: sign-off authority is limited to a gate's owner or listed approvers, overrides are restricted to release managers, and every decision is audit-logged.

Read the full detail on the security page.

Privacy & data handling

The app stores only the release-readiness content you author, Jira issue snapshots you link, and Atlassian account IDs for people — never names, emails, or avatars, which are resolved live from Jira at read time. It collects no credentials, no payment data, no analytics, no cookies, and no device data.

Read the privacy policy for what is stored, retained, and removed.

Compliance & hosting

  • Data residency. Forge hosted storage is pinned to — and migrates with — the data-residency location your admin chooses for the host product.
  • Platform certifications. Because the app runs on Forge and stores data in Atlassian's infrastructure, Atlassian's own security and compliance commitments (including SOC 2 and ISO 27001 for the underlying platform) apply to your data at rest. These are documented in the Atlassian Trust Center.
  • Runs on Atlassian. The app qualifies for Atlassian's Runs on Atlassian program, which technically enforces the zero-egress, Atlassian-only data posture described above.

Sub-processors

None. Atlassian hosts the platform the app runs on; no other party is involved in processing your data. There are no employees, contractors, or third-party sub-processors.

Permissions requested

  • read:jira-work — read issues, projects, and versions the current user can already see.
  • read:jira-user — resolve display names and avatars at render time.
  • storage:app — the app's own Forge SQL storage.

Scope changes require your admin's explicit re-consent through Atlassian's upgrade flow.

Reporting a vulnerability

If you believe you have found a security issue in Greenlight, email support@sanyasha.com with steps to reproduce where possible. We acknowledge reports within 2 business days and keep you informed through to resolution. We ask that you practice responsible disclosure and allow reasonable time to remediate before publishing.

Documents

Contact

Security, privacy, or compliance questions: support@sanyasha.com