attachmentAV for Atlassian Jira: Security

attachmentAV for Atlassian Jira is secure by default. When you upload an attachment, our scanners are notified, download the attachment, scan it, and delete it. We don’t keep a copy of your data.

Jurisdiction (#)

attachmentAV for Atlassian Jira scans attachments (process your data) in the jurisdiction/region/location of your choice to help you meet data residency requirements.

To choose a jurisdiction, follow Atlassian Support.

Permissions (#)

OAuth 2.0 scopes (#)

attachmentAV for Atlassian Jira requests the following OAuth 2.0 scopes during installation to access your Jira instance:

CategoryScopeAtlassian descriptionattachmentAV description
Forge platform scopestorage:appEnables the App storage API.to store scan results & configuration on the Atlassian platform
Forge platform scoperead:app-system-tokenEnables Forge to pass a token to a remote backend, that can be used to invoke Atlassian product REST APIs with the permissions of the app “bot” user.to run the full scan outside of Forge on our backend
Jira granular scoperead:application-role:jiraView application rolesto get issue attachment metadata
Jira granular scoperead:attachment:jiraView attachmentsto get issue attachment download URL & metadata
Jira granular scoperead:audit-log:jiraView audit logsto list attachments in backend
Jira granular scoperead:avatar:jiraView avatarsto add a comment to an issue, get issue metadata, get issue attachment metadata, list attachments in backend
Jira granular scoperead:comment.property:jiraView comment propertiesto add a comment to an issue
Jira granular scoperead:comment:jiraView commentsto add a comment to an issue
Jira granular scoperead:field-configuration:jiraRead field configurationsto get issue metadata, list attachments in backend
Jira granular scoperead:group:jiraView groupsto add a comment to an issue, get issue attachment metadata
Jira granular scoperead:issue-details:jiraView issue detailsto list attachments in backend
Jira granular scoperead:issue-meta:jiraView issue metato get issue metadata, list attachments in backend
Jira granular scoperead:issue-security-level:jiraView issue security levelsto get issue metadata
Jira granular scoperead:issue.changelog:jiraView issue changelogsto get issue metadata
Jira granular scoperead:issue.vote:jirato get issue metadata
Jira granular scoperead:issue:jiraView issuesto get issue metadata
Jira granular scoperead:project-role:jiraView project rolesto add a comment to an issue
Jira granular scoperead:project:jiraView projectsto add a comment to an issue
Jira granular scoperead:status:jiraView statusesto get issue metadata
Jira granular scoperead:user:jiraView usersto add a comment to an issue, get issue metadata, get issue attachment metadata
Jira granular scopedelete:attachment:jiraDelete attachmentsto delete infected/unscannable attachment
Jira granular scopewrite:comment:jiraCreate and update commentsto add a comment to an issue
Jira classic scopesread:jira-workView Jira issue datarequired by event avi:jira:created:attachment

Encryption (#)

In transit (#)

All network communication is TLS encrypted using HTTPS.

At rest (#)

Your attachments are temporarily stored on encrypted disks on our scanners. Attachments are deleted right after the scan.

Need more help?

Write us, and we'll get back to you as soon as we can.

Send us an email