oc Outlier Crosstab Narrow tools for Jira

Trust · for security reviewers and site admins

What a security review asks, answered once, for every tool. Where the tools differ, both answers are printed.

Each tool's own security and privacy pages say in full what it reads. This page puts the answers side by side, and says once what is the same for both: who you are dealing with, and what happens if that person stops.

Side by side

The questions a reviewer asks, one column per tool.

QuestionOutlierCrosstab
Where does it run?On Atlassian's infrastructure. No vendor backend, and nothing that calls home.1In a Forge function inside Atlassian's infrastructure. No server or database of ours.2
What does it read?The created, updated and status fields, and each issue's changelog. Content in the changelog is dropped before anything is derived.3The issues your saved filter or search selects, and the fields you put on the axes and add up. differs4
What does it keep?Issue keys, status ids and timestamps, and the board's own settings.3What you ask it to keep - grids, setups, schedules - and what it needs to answer quickly, in your site's app storage. The only ticket text kept is an epic's own summary. differs52
Anything about a person?No field named for a person anywhere in the schema. A write that carries one is refused.3No axis can be a person: not assignee, not reporter, not creator, not any user field.6
Does anything leave Atlassian?Not because of the app. An Automation rule you write may send the morning's text on.7No. The manifest declares no external host.8
Does it change your issues?No. Every scope that reads Jira is read-only; the app has no write scope.9No. No issue is created, edited, transitioned or commented on.2
A published data processing agreement?No.No.

Every answer links to the page that says it in full. A row marked differs is one where the two tools work differently.

Who you deal with

One person. A sole trader, not a company.

The vendor of both tools is Oleksandr Chmut, a sole trader registered in Ukraine, trading as oc. There is no team behind either of them.10

A reported problem goes straight to the person who wrote the code and can fix it.10

Reporting a flaw

Write to support@chmut.com. No proof of concept needed.

Say what you found and, if you can, how to reproduce it. You can also report it to Atlassian, who raise it in their Marketplace Security project with a remediation due date. Either route reaches the same person.1112

SeverityCVSSFixed within
Critical9.0 and above10 days
High7.0 to 8.94 weeks
Medium4.0 to 6.912 weeks
Lowbelow 4.025 weeks

Both tools are held to these timeframes. Atlassian sets them for Marketplace apps.

How fast

A reply is not a fix. Each tool says which clock it means.

Outlier

A vulnerability report gets a human reply within three working days. That is a commitment about acknowledgement, not about a fix.11

Crosstab

An ordinary question is answered within 48 hours, between 09:00 and 19:00 Europe/Kyiv, Monday to Friday, except Ukrainian public holidays. A vulnerability follows the table above.13

Incidents

Each tool has its own plan. The fix is usually a rollback.

Outlier14
  • 24 hours Atlassian is notified, as a P1, from becoming aware.
  • Every 6 hours Updates to Atlassian while it is open.
  • 72 hours Affected customers are notified, from identification.
Crosstab15
  • 1 working day The report is answered by the person who wrote the code.
  • 72 hours Affected sites are told, if their data is involved.
  • Same working day The build is rolled back, once the fault is confirmed and where a rollback is the fix.
  • 5 working days A written account, to anybody who was told.

A Forge deploy reaches every installation without any action by you, so rolling back to the last good revision fixes every site at once, with nothing for an administrator to apply.14

How an incident is noticed is the thin part: in almost every case, because somebody writes to support. There is no alerting, and nothing watches the logs.1617

If the one person stops

You would keep the tools. They would stop improving.

No report disappears, and no number is lost. Neither tool runs on anything of ours, so there is no switch that gets thrown when somebody stops working on it: they run inside your Atlassian site, and keep running until the platform changes under them.118

What stops is the part a person does: new versions, answers to support, and following the platform when it changes. Nothing is promised beyond that today: no escrow, no successor, no notice period.1

What this page does not claim

Said here so a reviewer does not have to find it.

  • No independent review. Nobody outside the studio has audited either tool. Outlier holds no compliance certification and has not been penetration-tested.1719
  • No team, no on-call rota, no second pair of eyes on a change.1710
  • No monitoring that would notice a fault before a customer does.1716

Receipts

Where every answer on this page is written in full.

  1. 1
    Outlier's front page: who is behind it, and what happens if that stops.outlier.chmut.com/#who-is-behind-it-and-what-happens-if-that-stops
  2. 2
    Crosstab's security page: where the data lives.crosstab.chmut.com/security#where-the-data-lives
  3. 3
    Outlier's security page: what is read, and what is kept.outlier.chmut.com/security#what-is-read-and-what-is-kept
  4. 4
    Crosstab's privacy page: what the app reads.crosstab.chmut.com/privacy#what-the-app-reads
  5. 5
    Crosstab's privacy page: what the app stores.crosstab.chmut.com/privacy#what-the-app-stores
  6. 6
    Crosstab's security page: no person as an axis.crosstab.chmut.com/security#no-person-as-an-axis
  7. 7
    Outlier's security page: what can leave your site, and who decides.outlier.chmut.com/security#what-can-leave-your-site-and-who-decides
  8. 8
    Crosstab's security page: at a glance.crosstab.chmut.com/security#at-a-glance
  9. 9
    Outlier's privacy policy: what it asks for.outlier.chmut.com/privacy#what-it-asks-for
  10. 10
    Crosstab's security page: who stands behind this.crosstab.chmut.com/security#who-stands-behind-this
  11. 11
    Outlier's security page: reporting a vulnerability.outlier.chmut.com/security#reporting-a-vulnerability
  12. 12
    Crosstab's security page: reporting a vulnerability.crosstab.chmut.com/security#reporting-a-vulnerability
  13. 13
    Crosstab's security page: response times.crosstab.chmut.com/security#response-times
  14. 14
    Outlier's security page: if there is an incident.outlier.chmut.com/security#if-there-is-an-incident
  15. 15
    Crosstab's security page: what happens when.crosstab.chmut.com/security#what-happens-when
  16. 16
    Crosstab's security page: how one is noticed.crosstab.chmut.com/security#how-one-is-noticed
  17. 17
    Outlier's security page: what this page does not claim.outlier.chmut.com/security#what-this-page-does-not-claim
  18. 18
    Crosstab's security page: if the one person stops.crosstab.chmut.com/security#if-the-one-person-stops
  19. 19
    Crosstab's security page: what is not claimed.crosstab.chmut.com/security#what-is-not-claimed