Snapshot 58162
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Skip to content Trust and data handling Your data never passes through Oktul's infrastructure Every Oktul application is built on Atlassian Forge. Atlassian operates the runtime, stores the data and enforces the restrictions you set, so no part of Oktul's infrastructure sits between your users and their work. View applicationsAsk a question directly Built on Atlassian Forge The code runs on Atlassian's platform. We write it Forge is Atlassian's own application runtime, and we build on nothing else, so the answers below hold for every application we ship. RuntimeAtlassian Forge Data storageYour Atlassian site Oktul infrastructureNone 1 The code runs in Atlassian's runtime, on Atlassian's compute Forge functions run in Atlassian's own environment, isolated per application, under the scopes the application declares at install. We never hold an API token or service account of yours, there is no hosting of ours for you to assess, and no Oktul outage can affect your apps. 2 Application data sits in Atlassian's database and stays on your site What an application stores of its own goes in Forge's database, which Atlassian keeps encrypted and isolated to your site. Data that belongs to a work item stays on the work item. If you change your data residency, the data moves with your site. 3 Where an application may connect and send data is listed in its manifest file, and a proxy enforces it A Forge app can reach only the hosts named in its manifest. Every outbound request passes through an Atlassian proxy that enforces that list at runtime, whatever the application tries. The manifest ships with the application, so you can read the list before you install. Any host added later needs a fresh approval from your administrator. 4 Runs on Atlassian is Atlassian's verdict, not our claim Atlassian applies that badge automatically to applications that send no data outside the Atlassian ecosystem and use Atlassian's storage. It is granted to each application separately. When an application sends data outside AtlassianIn that case we document it in the application's documentation: what leaves, where it goes, why, and what is done with it. The documentation is public, so you can read it before you install. If you have questions, we are always ready to help. App logs Error logs reach us by default. You can switch them off Atlassian can share logs, analytics and custom metrics from your site with an app's developer, and gives each its own switch. Below is what we log, and how to turn all three off. When you install a Forge app, Atlassian turns on log sharing by default and the developer gets access to that application's logs for your site. It applies to every Forge app on your site, ours included. Our logs record errors and nothing else: no work item content and no user records. Atlassian's logging guidelines (opens in a new tab) tell developers not to log names, email addresses, usernames or user-generated content, and we follow them. You do not have to take our word for it. Download the logs from your admin settings and see exactly what we receive. Turning off error log sharing with the vendor Go to admin.atlassian.com and select your organisation. Select Apps, then Sites, then the site you are administering. Select Connected apps, then the application. In the Details tab, turn off Logs access, Analytics access and Custom metrics access. The switches are independent, so turning one off leaves the other two as they were. Marketplace reporting still shows us your licence, whatever you set here. The same page downloads the logs, and the audit log keeps your log sharing history. With logs off we cannot diagnose a fault from our side, so we will ask you for the log file instead, which is slower. Support and response times Every request gets a reply within 24 hours The reply comes from the people who wrote the code. Time to a solution depends on what is wrong, so it is set per severity. Resolution times are set according to the Atlassian Fortified programme. Priority What it means Time to solution Critical The application is down, or a technical issue is severely blocking the business. 7 calendar days Critical security A vulnerability scoring CVSS 9.0 or above. An immediate threat to cloud infrastructure or to data. 7 calendar days High security A vulnerability scoring CVSS 7.0 or above. Significant security exposure with no simple workaround. 14 calendar days Medium security A vulnerability scoring CVSS 4.0 to 6.9. A moderate security risk. 28 calendar days Low security A vulnerability scoring below CVSS 4.0. A minor security issue with low potential for exploitation. 56 calendar days Standard support request A question, a configuration problem, a documentation gap or a feature request. Nothing is broken and nothing is exposed. No resolution target. The 24-hour response applies as it does to everything else The clock runs on requests raised in the Help Center. Email to support@oktul.com opens a request in the same service desk, with the same targets. Email to any other address is not measured under the service level agreement. A security issue's severity is the vulnerability's CVSS score, not our opinion. For a technical issue we set the severity and explain it where needed. The SLA table covers our response, not the platform's availability: Forge is Atlassian's and runs on Atlassian's infrastructure. Atlassian publishes its own service status and service level agreements. Initial response, every request Within 24 hours, Monday to Friday. A request raised outside the working week starts its clock when the next one begins. This applies to every priority below, including those with no resolution target. Working week Monday to Friday, 09:00 to 17:00, Europe/Tallinn. Resolution targets are in calendar days, so weekends count. Raise a request in the Help Center (opens in a new tab) What we publish Our security self-assessment and legal documents are public Every claim on this page is either Atlassian's, checkable in their documentation, or ours, written down in one of these. Our CSA STAR self-assessment Oktul is listed in the Cloud Security Alliance STAR Registry at Level 1. That is a self-assessment, not an audit: we completed the CAIQ Lite questionnaire, all 138 questions across the 17 Cloud Controls Matrix domains, and published it for anyone to read. This entry covers the company only. An application assessed in its own right has its listing on its own product page. Oktul is implementing an information security management system to ISO/IEC 27001 and expects to be certified by March 2027 at the latest. Read the company assessment on the STAR Registry (opens in a new tab) The documents this rests on Privacy policyCookie noticeWebsite termsApplication licenceData processing addendum If something goes wrong We have had no security breach or incident to date. If one occurs, we tell Atlassian within one hour and, where personal data is affected, the Estonian Data Protection Inspectorate within 72 hours, as the GDPR requires. Reporting a vulnerability Raise it in the Help Center (opens in a new tab), or email support@oktul.com. Both open a request in the same service desk, so the report gets a reference and a measured response target. A request raised in the Help Center usually gets a more personal and faster answer, because its form asks the questions an email thread can leave out. Common questions What security and procurement specialists ask us If you didn't find your answer here, don't hesitate to contact us. Do Oktul applications send data outside the Atlassian ecosystem? Your data is yours, and it stays on your Atlassian site wherever a feature allows. The applications run on Atlassian Forge inside your own Atlassian site, not on infrastructure we operate. Where a feature has to send data out, such as signing a Confluence page, we send only what it needs. Every party in that path is named in the application’s documentation, with what it receives. Who maintains the applications, and what happens if they stop? Solution architects named on the company page, holding twenty-three Atlassian certifications and accreditations between them. Oktul OÜ is registered in Estonia under registry code 17589681. The applications run on Atlassian Forge, so your site depends on no part of Oktul’s infrastructure. Atlassian runs the code on its own platform, and your configuration and data stay on your site whatever happens to us. How fast do you respond when something breaks? An initial response within 24 hours, Monday to Friday, on a request raised in our Help Center. Use it rather than email: a Help Center request has a type, a reference and a measured response target, while an email has a person reading it and nothing measuring it. The Help Center is public, needs no account or Atlassian licence, and asks only for an email address to reply to. It takes incidents, bugs, questions, demo and feature requests, and requests for an application we have not built yet. Why trust a small vendor like Oktul? Because we spent years evaluating Marketplace apps for banks and public sector clients, and our applications fix the shortcomings we found there. They run on Forge, so they depend on no part of our infrastructure. Every claim we make is checkable: the certifications are listed with dates, and the response time is written into an SLA. Is Oktul an Atlassian partner? Yes. Oktul is an Atlassian Marketplace Partner. Our partner status gives us access to the latest updates in the Atlassian ecosystem, opportunities to keep learning and much more. What does it cost to evaluate one? Pricing, trials and billing run through the Atlassian Marketplace, on the same terms as every other app on your site. The application appears on your existing Atlassian invoice, with no new supplier to onboard, no purchase order and no review of our payment handling. The documentation is public, so you can read it without a trial.