Security at Sprint Buddy
Your sprint data is sensitive. Here is exactly how we protect it across the stack — encryption, isolation, monitoring, and process.
Security
Encryption everywhere
TLS 1.3 in transit. AES-256 at rest. Atlassian OAuth credentials stored encrypted with per-tenant keys.
Row-level isolation
Every row is scoped to a workspace. Postgres RLS policies enforced at the database — not just the app layer.
SSO & SAML
Team plan supports SAML 2.0 with major IdPs. Optional enforcement of SSO-only sign-in.
EU data residency
Primary database and backups stored in EU regions. Backups encrypted and retained for 30 days.
Audit logging
Every admin action, integration change, and generated output is logged with actor, IP, and timestamp.
Responsible disclosure
Found a vulnerability? Email security@sprintbuddy.app — we acknowledge within 24 hours.
Compliance & posture
- GDPR-aligned data processing addendum on request
- SOC 2 Type II — audit in progress (target Q4 2026)
- Quarterly automated penetration tests
- Dependency scanning and patching SLA: 7 days for criticals
- Least-privilege access — staff access requires SSO + MFA
data handling
- LLM providers contractually bound to zero-retention
- Your Jira content is never used to train third-party models
- You can purge generated artifacts at any time
- Disconnecting Jira deletes synced cache within 7 days
Report a vulnerability
Send a detailed report to security@sprintbuddy.app. Please give us 90 days before public disclosure. We do not pursue legal action against good-faith researchers who follow this policy.