Reporting a vulnerability

If you think you've found a security issue in Pokerly or on this website, please email contact@umaylabs.com. Please don't report it in public first.

It helps if your report includes:

  • Which part is affected: the Pokerly app in Jira Cloud, or the website pokerly.umaylabs.com
  • What the issue is and what an attacker could do with it
  • Steps to reproduce it, with proof-of-concept details if you have them
  • How you'd like to be credited, if at all

Don't include real customer data, passwords or API tokens in your report. If you need to show data access, use data from your own test site.

What happens next

  1. We acknowledge your report within 3 business days.
  2. We confirm the issue and rate its severity using CVSS.
  3. We fix it within the timeframe for its severity (see below) and keep you updated along the way.
  4. We let you know when it's fixed, and credit you if you'd like.

Severity and fix timeframes

Pokerly follows Atlassian's Security Bug Fix Policy for Marketplace apps. The fix timeframe depends on the vulnerability's CVSS score:

Fix timeframes by severity
Severity CVSS score Fix timeframe
Critical 9.0 – 10.0 Within 10 days
High 7.0 – 8.9 Within 4 weeks
Medium 4.0 – 6.9 Within 12 weeks
Low 0.1 – 3.9 Within 25 weeks

We also work with Atlassian on vulnerabilities it reports to us through the Atlassian Marketplace Security (AMS) process.

Security incidents

If we find a security incident that affects Pokerly or its customers' data, we will:

  • Notify Atlassian no later than 24 hours after we discover it
  • Notify affected customers directly, within 72 hours of identifying the incident where feasible
  • Contain the incident, fix the cause, and review what happened so it doesn't happen again

Guidelines for security research

When you look into Pokerly's security, please:

  • Test only on a Jira Cloud site you own or are allowed to test
  • Never access, change or delete other people's data
  • Don't run denial-of-service attacks, spam, social engineering or physical attacks
  • Give us a reasonable amount of time to fix the issue before you disclose it publicly

Vulnerabilities in Jira, Atlassian Forge or other Atlassian products and infrastructure belong to Atlassian. Please report those to Atlassian.

How Pokerly is secured

  • Built on Atlassian Forge. Pokerly has no external servers and makes no external data egress calls. App data is kept in Forge-hosted storage within the customer's Atlassian environment.
  • Runs as the signed-in user. Jira API calls are made as the signed-in user (asUser), so Jira permissions are respected and people only see issues they're allowed to see.
  • Checked on the server. Every change to data is validated server-side against the user's Pokerly role.
  • Minimal permissions. read:jira-work, write:jira-work, read:jira-user and storage:app. No external permissions.
  • Limited personal data. Pokerly doesn't store email addresses. See the data and privacy statement for what is stored and for how long.

This website

pokerly.umaylabs.com is a static website served over HTTPS. It has no accounts, forms, analytics or tracking cookies, and sends security headers including a Content Security Policy. Our security.txt lists the same contact details as this page.

Contact

Security reports: contact@umaylabs.com. For anything else, see Support.