โ Cody Labs projects ยท Support
Security policy
Cody Labs. Effective 21 August 2026.
Cody Labs builds Atlassian Forge apps, Google Workspace add-ons, monday.com apps, and standalone import and export tools. This page sets out our supported versions, the security model behind our Atlassian Forge apps, and how to report a vulnerability. Each product's own privacy page, linked from its product page, describes exactly what data that product accesses and how that data flows.
Supported versions
Only the latest production release of each Cody Labs product is supported. Security fixes are released through that product's live deployment, whether the distribution channel is Atlassian Forge, Google Workspace Marketplace, monday.com, or another marketplace, and through the corresponding listing version.
Security model: Atlassian Forge apps
Excel Import & Export for Jira, Assets Excel Sync for Jira Service Management, and Worklog Export for Jira are built on Atlassian Forge and run entirely inside Atlassian's cloud platform, acting as the signed-in user with that user's own Jira permissions.
- Jira and Assets calls use Forge Bridge
requestJiraas the signed-in user. No separate Jira API token, password, or external OAuth credential is collected. - Issue rows, Assets objects, and workbooks are generated and parsed inside Forge Custom UI in your browser. They are never sent to a Cody Labs server or a third-party service.
- Forge KVS storage holds only per-user export templates and import mapping presets. It does not store exported rows or uploaded workbooks.
- Bulk writes require a dry-run review before you can commit a change to Jira.
- These apps have no Forge Remote, external egress allowlist, anonymous endpoint, SQL database, Rovo action, or arbitrary code execution surface.
Dependencies are checked in CI and by Dependabot. Each app's committed Custom UI dependency tree must pass npm audit --audit-level=moderate with no known vulnerabilities before release.
Other products
Our Google Workspace add-ons, monday.com apps, and standalone tools run on their own host platforms under that platform's own permission model. Their data flow, storage, and third-party dependencies are documented on each product's own privacy page rather than repeated here, since the details differ by platform.
Reporting a vulnerability
Report suspected vulnerabilities privately to [email protected]. Include the product name, affected workflow, reproduction steps, impact, and any supporting evidence. Do not open a public GitHub issue for an undisclosed vulnerability.
Cody Labs will confirm receipt, investigate, and coordinate remediation and disclosure with the reporter. Security incidents involving Atlassian Marketplace, Google Workspace Marketplace, or monday.com customers are also reported through that marketplace's own required process where one applies.
Contact
Email [email protected] for anything on this page.
Atlassian, Jira, and Forge are trademarks of Atlassian Pty Ltd. Google Workspace is a trademark of Google LLC. monday.com is a trademark of monday.com Ltd. Cody Labs products are independent and are not affiliated with or endorsed by these companies. This page is governed by the laws of Australia.