Security — Time Off

Last updated: 26 August 2026

This page describes how Time Off is built, hosted and maintained, and how to report a security problem. It is deliberately separate from the Privacy Policy, which covers what the app stores and who can read it.

How the app is hosted

Time Off runs entirely on Atlassian Forge. We operate no servers, no databases and no infrastructure of our own. The app's code runs on Atlassian's platform and its data lives in Forge storage, inside the Atlassian cloud region of your own Jira site. Hosting, network security, tenant isolation and physical security are therefore Atlassian's, under Atlassian's own security programme and certifications.

No data leaves your site

The app's manifest declares no external permissions and no egress. The app makes no request to any host outside Atlassian, which means data physically cannot be sent anywhere else. There is no analytics, no telemetry and no third-party error reporting. There are no sub-processors: nothing about your site or your people reaches us or anyone else.

Encryption

Permissions and access control

Who may approve, change or cancel a leave request is decided in the app's own engine from the permissions Jira reports, and enforced in the resolver on the server — never by hiding a button on screen. The note a person attaches to a request can be read only by that person and by the people who can approve leave; the team calendar shows dates and nothing else.

Least privilege

Time Off asks for no content scopes at all: it cannot read a Jira issue, a comment or an attachment. It reads who you are so that lists show people instead of account identifiers, and it reads the permissions Jira reports so it can tell who may approve leave. The full list of scopes, with the reason for each one, is published on the app's Marketplace listing and was given in writing to the Atlassian app review team.

How the app is built and released

Reporting a vulnerability

Write to support@saoirsesoftware.com, or open a request on our support portal. Please include what you found, how to reproduce it, and what an attacker could do with it. Every report is acknowledged in writing within one business day and given a single owner. We do not take legal action against anyone who reports a problem to us in good faith and gives us reasonable time to fix it.

We triage within three business days, using CVSS v3 and Atlassian's severity levels, and we follow the Atlassian Marketplace security bug fix policy: critical within 2 weeks, high within 4 weeks, medium within 6 weeks, low within 6 months, measured from confirmation.

If something goes wrong

We keep a written incident response plan covering intake, triage, containment, notification and the write-up afterwards. In short:

Keeping and erasing data

Once a week, on its own, the app asks Atlassian whether any account it still holds information about has been closed or updated, and erases or refreshes its record accordingly. When an administrator uninstalls the app, Atlassian deletes the app's storage for that site as part of the normal uninstall. A request to remove data sooner, or to see what is held, is handled within 30 days — see the Privacy Policy.

What we do not have

We would rather say this plainly than let a checklist imply otherwise. Saoirse Software is a small Irish software company, and today we run no bug bounty programme, no external penetration test and no ISO 27001 or SOC 2 certification. Nothing on this page is claimed unless it is actually in place. When that changes, this page changes with it, and the date at the top changes too.

Contact

Security contact: support@saoirsesoftware.com — monitored Monday to Friday, 09:00–17:00 Europe/Dublin. The same address is registered on the app's Marketplace listing and on our partner profile.