Security Policy

Auto-Triage AI — Sprintloom

Last updated: May 1, 2026

1. Overview

Sprintloom builds and operates the Auto-Triage AI app for Atlassian Jira. This Security Policy describes how we manage security across our app, infrastructure, and related services — including the SprintLoom hosted LLM inference endpoint at autotriage-api.sprintloom.com.

This policy applies to:

2. Security Incident Handling

2.1 Incident Response Process

Security incidents are handled through the following process:

  1. Detection: Automated monitoring on all SprintLoom infrastructure detects anomalous activity, failed authentication attempts, and unusual API traffic patterns.
  2. Triage: Incidents are classified by severity within 1 hour of detection. Severity levels:
  1. Containment: Affected systems are isolated. Credentials are rotated if suspected compromised.
  2. Notification: Affected customers are notified within 72 hours per GDPR/data breach notification requirements.
  3. Remediation: Root cause analysis is performed and fixes are deployed.
  4. Post-mortem: A written incident report is produced within 14 days and shared with affected customers on request.

2.2 Contact for Security Issues

If you discover a security vulnerability or believe an incident has occurred, contact us immediately:

Security Contact

Email: [email protected]

We aim to acknowledge security reports within 4 hours and provide an initial assessment within 24 hours.

For general support, use [email protected].

3. Vulnerability Management

3.1 Continuous Scanning

All SprintLoom infrastructure is scanned for vulnerabilities on a recurring basis. This includes:

3.2 Patch Management

Security patches are applied on the following schedule:

3.3 Penetration Testing

SprintLoom conducts periodic security assessments against its public-facing infrastructure. Critical findings are prioritized and remediated before the next release cycle.

4. Security Controls

4.1 Access Controls

4.2 Infrastructure

5. Encryption & Data in Transit

6. Data Storage & Access

7. Prompt Injection Defenses

Auto-Triage AI implements multiple layers of protection against prompt injection attacks:

8. Atlassian Forge Security

9. Compliance & Certifications

SprintLoom is committed to maintaining security practices aligned with industry standards. Currently applicable certifications and practices:

10. Contact

For security vulnerabilities, incidents, or questions about this policy:

Security & Compliance Contact

Security reports: [email protected]

General inquiries: [email protected]

Website: https://sprintloom.com/contact

We aim to respond to security reports within 4 hours and provide a detailed assessment within 5 business days.