← Filter Delta overview

Filter Delta for Jira / Security

Your permissions.
The same boundaries.

How Filter Delta controls access to personal monitors and where to report a security concern.

Jira Cloud Preparing for public release

Updated 23 September 2026 · Pre-release product information

Hosted on Forge

Filter Delta runs on Atlassian Forge with Forge hosted storage, queued workers and scheduled tasks. The app declares no external hosts, remotes, external authentication providers, analytics services or customer-supplied API tokens.

The Untiefe website and email service are separate. Their providers are described in the website privacy notice.

Personal monitors and Jira access

  • Monitor ownership comes from trusted Forge context, rather than an owner identity submitted by the browser.
  • Server-side resolver and worker paths check ownership of monitors and requests.
  • Interactive issue details are loaded with the viewing user’s current Jira permissions.
  • Background scans use the monitor owner’s Jira access through Forge offline user impersonation. If that access fails, there is no fallback to broader app-level Jira access.

The app reads Jira filters and search results. It does not write or modify Jira issues or saved filters.

What the app permissions are for

read:jira-work
Read filters and result membership, display current issue keys and summaries, and run scans using the owner’s access.
storage:app
Keep monitor configuration, bounded history, queued request state, retention and deletion records in Forge.
report:personal-data
Report stored owner account IDs through Forge’s privacy API and respond to account lifecycle changes.

Minimising stored issue content

Snapshots retain issue IDs rather than issue titles, descriptions, comments or attachments. Current keys and summaries are loaded only on view and are not stored. Owner account IDs and monitor settings, including the source filter or JQL, are stored separately.

See privacy and app data for the complete inventory and retention limits, and data deletion for the available controls.

Report a vulnerability

Email info@untiefe.dev with “Filter Delta security report” in the subject.

Include the affected version if visible, Jira Cloud context, an approximate timestamp, a description of the possible impact, and reproduction steps using synthetic data where possible. Visible request IDs and sanitised screenshots can help.

Do not send real customer secrets, Atlassian tokens, identity documents, private Jira content or unrelated personal data. Begin with a short description so an appropriate way to share sensitive details can be agreed.

Reports are handled directly by the developer. No guaranteed acknowledgement or resolution time, dedicated incident status service or bug bounty is currently offered. General product questions belong at Untiefe support.

Scope of this information

This page describes the current implementation, not a security certification. Filter Delta is not yet publicly listed on the Atlassian Marketplace. No Marketplace approval, security programme badge or independent certification is claimed here.