Planning Poker for Jira

Security

Vulnerability Disclosure Policy — Last updated: 3 June 2026

Reporting a vulnerability

We take security seriously. If you believe you have found a security vulnerability in Planning Poker for Jira, please report it to us responsibly by emailing:

Security contact

Kee Ling Xuan — lingxuan.kee@yycadvisors.com

Subject line: [SECURITY] Planning Poker for Jira

Please include as much of the following as possible to help us reproduce and validate the issue:

Our commitment to you

Responsible disclosure guidelines

We ask that you:

We will not take legal action against security researchers who discover and report vulnerabilities in good faith following these guidelines.

Scope

This policy covers:

Vulnerabilities in the underlying Atlassian Forge platform or Jira Cloud itself should be reported directly to Atlassian at atlassian.com/trust/security.