Security

MarginRadar is a Forge app that Runs on Atlassian. Your data stays in Atlassian, and the app makes no calls to anything outside it.

Reviewed against the MarginRadar source code on 9 October 2026.

Architecture

MarginRadar is built entirely on Atlassian Forge and declares no remotes and no external permissions, which is what Atlassian's Runs on Atlassian programme requires. The badge itself is awarded by Atlassian. The app has no servers of its own.

  • User interface: Forge Custom UI (React, Atlassian Design System) shown inside Jira: project page, issue and epic panel, dashboard gadget and admin pages. It only talks to the app's own Forge functions. The manifest asks Atlassian only to allow inline styles for it; it allows no external scripts, frames or network access.
  • Logic: Forge functions that read Jira data and calculate cost, revenue, margin, burn rate and forecasts. They run on worklog events from Jira and on a daily scheduled job that refreshes the calculated figures.
  • Storage: Forge SQL and Forge Key-Value Store (hosted storage), on Atlassian infrastructure.
  • Rovo: the optional agent's actions are Forge modules that read MarginRadar data inside Forge.
  • No remotes: no Forge Remote, no Connect, no backend operated by Radrly, and no public REST API.

Data flow

MarginRadar data flow Inside the Atlassian cloud, the MarginRadar Forge app reads worklogs and issues from Jira Cloud, stores its data in Forge SQL and Key-Value Store, and can post alert comments back to Jira. Nothing leaves Atlassian: there is no connection to external servers, third-party APIs or AI services. Atlassian cloud (your site's data residency) Jira Cloud site Projects, issues, epics, worklogs, users reads, events alert comments MarginRadar (Forge app) Custom UI · functions · Rovo actions Runs on Atlassian storage:app Forge SQL + Key-Value Store Budgets, rates, roles, audit log, calculated figures ✕ no egress External servers, third-party APIs, AI services None. MarginRadar makes no outbound calls.
  1. The app reads projects, issues, epics and worklogs from Jira through Forge, and receives events when worklogs are created, updated or deleted.
  2. Functions calculate cost, revenue, margin, burn rate and (Advanced) the 14-day forecast.
  3. Results and settings are stored in Forge SQL and Key-Value Store.
  4. Users see the results inside Jira. Only the signed-in user's browser and Atlassian are involved.
  5. Optional (Advanced): the app posts an alert as a comment on the alert work item you choose, or on the epic of an epic budget.
  6. Optional (Advanced): the Rovo agent asks MarginRadar's actions for data, inside Atlassian.

Scopes

MarginRadar requests the minimum Forge scopes it needs, and no others.

ScopeReason
read:jira-workRead projects, issues, epics and worklogs, and receive worklog events, to calculate cost, revenue, margin and budget usage.
write:jira-workOnly to post budget alert comments on issues and epics (Advanced). MarginRadar never edits issues, fields or worklogs.
read:jira-userRead user names and roles so that people can be identified in rate cards and role assignments. User names are shown in the interface and not stored.
storage:appStore the app's data in Forge hosted storage (Forge SQL and Key-Value Store).

No egress

MarginRadar declares no external hosts and makes no outbound network calls. It uses no Forge Remote, no Connect and no fetch to external services. Radrly receives no customer data, and the app sends no telemetry to Radrly or any third party. The only outbound requests in the code are authenticated calls to Jira through Forge.

Requests to Jira use Forge's authenticated platform APIs. The app does not handle passwords, personal access tokens or shared secrets.

Data protection

  • At rest: data is stored in Atlassian's Forge hosted storage, which Atlassian encrypts at rest.
  • In transit: traffic between the browser, Jira and Forge uses TLS, managed by Atlassian.
  • Data residency: app data follows the data residency location of your Jira site. Radrly does not store data anywhere else.
  • Minimisation: only account IDs are stored as user identifiers. Worklog comments, issue summaries and issue descriptions are not stored.
  • Logs: the app logs only schema-migration status and error messages. It does not log account IDs, worklog data or comments, and logs stay in the Forge developer console.

Access control

  • Role-based visibility: Finance, PM and Viewer roles control who can see and change rates, budgets and margins. The restrictions are enforced on the server side, in the same functions that the project page, gadget, CSV export and Rovo actions use, and not only hidden in the interface. By default Jira site admins are Finance, project admins are PM for their project, and everyone else is a Viewer.
  • Audit log: changes to rates, budgets, access and data are recorded with who made them, when, and the values before and after.
  • No Radrly backend: the app has no code path that sends your MarginRadar data to Radrly, and Radrly operates no server that holds it.

Data lifecycle

  1. Install: the app asks for the scopes above, and can import past worklogs on request.
  2. Use: data is updated as worklogs change in Jira.
  3. Delete in the app: Finance users can delete a project's data or all MarginRadar data at any time.
  4. Uninstall: the Forge platform soft-deletes the data and destroys it at the end of the retention period in Atlassian's SOC 2 report (a reinstall within 21 days can be relinked to the old data). Radrly keeps no copy.

See the Privacy Policy for details.

AI statement

MarginRadar does not call any external AI or LLM service. The optional MarginRadar Rovo agent runs inside Atlassian Rovo. Rovo's processing is provided by Atlassian under Atlassian's terms and AI trust policies, and the agent's actions read MarginRadar data inside Forge.

The same actions are also published as Rovo MCP tools. If your organisation lets people connect an MCP client to Atlassian, that client can call the tools with the person's own permissions and receives the results. This is controlled by your Atlassian settings, not by MarginRadar, and the tools respect the person's MarginRadar role.

Compliance

Radrly does not hold its own compliance certifications for MarginRadar at this time. Atlassian's platform certifications cover Forge hosting. We do not claim them as our own. We have not yet completed a CAIQ Lite questionnaire, and do not run a bug bounty program yet. Every change goes through automated checks (formatting, linting, type checking, unit tests and Forge lint) before it is deployed.

For data protection terms, see the Privacy Policy and the DPA (draft).

Reporting a vulnerability

If you believe you have found a security vulnerability in MarginRadar, please tell us privately so that we can fix it before it is made public.

Email: security@radrly.com

Please include:

  • A description of the issue and its potential impact.
  • Steps to reproduce, or a proof of concept.
  • The affected app version and Jira site (use a test site where possible).
  • Your contact details, if you want credit.

What to expect: we will acknowledge your report within 2 business days, keep you informed, and tell you when it is fixed. Please give us a reasonable time to fix the issue before sharing details, and do not access, change or delete data that is not yours, or disrupt other customers. Good-faith research that follows these rules will not be pursued legally by Radrly.

For general bugs and questions, use Support instead.