Trust · for security reviewers and site admins
What a security review asks, answered once, for every tool. Where the tools differ, both answers are printed.
Each tool's own security and privacy pages say in full what it reads. This page puts the answers side by side, and says once what is the same for both: who you are dealing with, and what happens if that person stops.
Printed, this page is an answer sheet you can attach to a vendor questionnaire, with every link's address spelled out.
Side by side
The questions a reviewer asks, one column per tool.
| Question | Outlier | Crosstab |
|---|---|---|
| Where does it run? | On Atlassian's infrastructure. No vendor backend, and nothing that calls home.1 | In a Forge function inside Atlassian's infrastructure. No server or database of ours.2 |
| What does it read? | The created, updated and status fields, and each issue's changelog. Content in the changelog is dropped before anything is derived.3 | The issues your saved filter or search selects, and the fields you put on the axes and add up. differs4 |
| What does it keep? | Issue keys, status ids and timestamps, and the board's own settings.3 | What you ask it to keep - grids, setups, schedules - and what it needs to answer quickly, in your site's app storage. The only ticket text kept is an epic's own summary. differs52 |
| Anything about a person? | No field named for a person anywhere in the schema. A write that carries one is refused.3 | No axis can be a person: not assignee, not reporter, not creator, not any user field.6 |
| Does anything leave Atlassian? | Not because of the app. An Automation rule you write may send the morning's text on.7 | No. The manifest declares no external host.8 |
| Does it change your issues? | No. Every scope that reads Jira is read-only; the app has no write scope.9 | No. No issue is created, edited, transitioned or commented on.2 |
| A published data processing agreement? | No. | No. |
Every answer links to the page that says it in full. A row marked differs is one where the two tools work differently.
Who you deal with
One person. A sole trader, not a company.
The vendor of both tools is Oleksandr Chmut, a sole trader registered in Ukraine, trading as oc. There is no team behind either of them.10
A reported problem goes straight to the person who wrote the code and can fix it.10
Reporting a flaw
Write to support@chmut.com. No proof of concept needed.
Say what you found and, if you can, how to reproduce it. You can also report it to Atlassian, who raise it in their Marketplace Security project with a remediation due date. Either route reaches the same person.1112
| Severity | CVSS | Fixed within |
|---|---|---|
| Critical | 9.0 and above | 10 days |
| High | 7.0 to 8.9 | 4 weeks |
| Medium | 4.0 to 6.9 | 12 weeks |
| Low | below 4.0 | 25 weeks |
Both tools are held to these timeframes. Atlassian sets them for Marketplace apps.
How fast
A reply is not a fix. Each tool says which clock it means.
A vulnerability report gets a human reply within three working days. That is a commitment about acknowledgement, not about a fix.11
An ordinary question is answered within 48 hours, between 09:00 and 19:00 Europe/Kyiv, Monday to Friday, except Ukrainian public holidays. A vulnerability follows the table above.13
Incidents
Each tool has its own plan. The fix is usually a rollback.
- 24 hours Atlassian is notified, as a P1, from becoming aware.
- Every 6 hours Updates to Atlassian while it is open.
- 72 hours Affected customers are notified, from identification.
- 1 working day The report is answered by the person who wrote the code.
- 72 hours Affected sites are told, if their data is involved.
- Same working day The build is rolled back, once the fault is confirmed and where a rollback is the fix.
- 5 working days A written account, to anybody who was told.
A Forge deploy reaches every installation without any action by you, so rolling back to the last good revision fixes every site at once, with nothing for an administrator to apply.14
How an incident is noticed is the thin part: in almost every case, because somebody writes to support. There is no alerting, and nothing watches the logs.1617
If the one person stops
You would keep the tools. They would stop improving.
No report disappears, and no number is lost. Neither tool runs on anything of ours, so there is no switch that gets thrown when somebody stops working on it: they run inside your Atlassian site, and keep running until the platform changes under them.118
What stops is the part a person does: new versions, answers to support, and following the platform when it changes. Nothing is promised beyond that today: no escrow, no successor, no notice period.1
What this page does not claim
Said here so a reviewer does not have to find it.
Receipts
Where every answer on this page is written in full.
- 1Outlier's front page: who is behind it, and what happens if that stops.outlier.chmut.com/#who-is-behind-it-and-what-happens-if-that-stops
- 2Crosstab's security page: where the data lives.crosstab.chmut.com/security#where-the-data-lives
- 3Outlier's security page: what is read, and what is kept.outlier.chmut.com/security#what-is-read-and-what-is-kept
- 4Crosstab's privacy page: what the app reads.crosstab.chmut.com/privacy#what-the-app-reads
- 5Crosstab's privacy page: what the app stores.crosstab.chmut.com/privacy#what-the-app-stores
- 6Crosstab's security page: no person as an axis.crosstab.chmut.com/security#no-person-as-an-axis
- 7Outlier's security page: what can leave your site, and who decides.outlier.chmut.com/security#what-can-leave-your-site-and-who-decides
- 8Crosstab's security page: at a glance.crosstab.chmut.com/security#at-a-glance
- 9Outlier's privacy policy: what it asks for.outlier.chmut.com/privacy#what-it-asks-for
- 10Crosstab's security page: who stands behind this.crosstab.chmut.com/security#who-stands-behind-this
- 11Outlier's security page: reporting a vulnerability.outlier.chmut.com/security#reporting-a-vulnerability
- 12Crosstab's security page: reporting a vulnerability.crosstab.chmut.com/security#reporting-a-vulnerability
- 13Crosstab's security page: response times.crosstab.chmut.com/security#response-times
- 14Outlier's security page: if there is an incident.outlier.chmut.com/security#if-there-is-an-incident
- 15Crosstab's security page: what happens when.crosstab.chmut.com/security#what-happens-when
- 16Crosstab's security page: how one is noticed.crosstab.chmut.com/security#how-one-is-noticed
- 17Outlier's security page: what this page does not claim.outlier.chmut.com/security#what-this-page-does-not-claim
- 18Crosstab's security page: if the one person stops.crosstab.chmut.com/security#if-the-one-person-stops
- 19Crosstab's security page: what is not claimed.crosstab.chmut.com/security#what-is-not-claimed