Security

Security at Sprint Buddy

Your sprint data is sensitive. Here is exactly how we protect it across the stack — encryption, isolation, monitoring, and process.

Security

Encryption everywhere

TLS 1.3 in transit. AES-256 at rest. Atlassian OAuth credentials stored encrypted with per-tenant keys.

Row-level isolation

Every row is scoped to a workspace. Postgres RLS policies enforced at the database — not just the app layer.

SSO & SAML

Team plan supports SAML 2.0 with major IdPs. Optional enforcement of SSO-only sign-in.

EU data residency

Primary database and backups stored in EU regions. Backups encrypted and retained for 30 days.

Audit logging

Every admin action, integration change, and generated output is logged with actor, IP, and timestamp.

Responsible disclosure

Found a vulnerability? Email security@sprintbuddy.app — we acknowledge within 24 hours.

Compliance & posture

  • GDPR-aligned data processing addendum on request
  • SOC 2 Type II — audit in progress (target Q4 2026)
  • Quarterly automated penetration tests
  • Dependency scanning and patching SLA: 7 days for criticals
  • Least-privilege access — staff access requires SSO + MFA

data handling

  • LLM providers contractually bound to zero-retention
  • Your Jira content is never used to train third-party models
  • You can purge generated artifacts at any time
  • Disconnecting Jira deletes synced cache within 7 days

Report a vulnerability

Send a detailed report to security@sprintbuddy.app. Please give us 90 days before public disclosure. We do not pursue legal action against good-faith researchers who follow this policy.