Reporting a vulnerability
If you think you've found a security issue in Questlog or on this website, please email contact@umaylabs.com. Please don't report it in public first.
It helps if your report includes:
- Which part is affected: the Questlog app in Jira Cloud, or the website questlog.umaylabs.com
- What the issue is and what an attacker could do with it
- Steps to reproduce it, with proof-of-concept details if you have them
- How you'd like to be credited, if at all
Don't include real customer data, passwords or API tokens in your report. If you need to show data access, use data from your own test site.
What happens next
- We acknowledge your report within 3 business days.
- We confirm the issue and rate its severity using CVSS.
- We fix it within the timeframe for its severity (see below) and keep you updated along the way.
- We let you know when it's fixed, and credit you if you'd like.
Severity and fix timeframes
Questlog follows Atlassian's Security Bug Fix Policy for Marketplace apps. The fix timeframe depends on the vulnerability's CVSS score:
| Severity | CVSS score | Fix timeframe |
|---|---|---|
| Critical | 9.0 – 10.0 | Within 10 days |
| High | 7.0 – 8.9 | Within 4 weeks |
| Medium | 4.0 – 6.9 | Within 12 weeks |
| Low | 0.1 – 3.9 | Within 25 weeks |
We also work with Atlassian on vulnerabilities it reports to us through the Atlassian Marketplace Security (AMS) process.
Security incidents
If we find a security incident that affects Questlog or its customers' data, we will:
- Notify Atlassian no later than 24 hours after we discover it
- Notify affected customers directly, within 72 hours of identifying the incident where feasible
- Contain the incident, fix the cause, and review what happened so it doesn't happen again
Guidelines for security research
When you look into Questlog's security, please:
- Test only on a Jira Cloud site you own or are allowed to test
- Never access, change or delete other people's data
- Don't run denial-of-service attacks, spam, social engineering or physical attacks
- Give us a reasonable amount of time to fix the issue before you disclose it publicly
Vulnerabilities in Jira, Atlassian Forge or other Atlassian products and infrastructure belong to Atlassian. Please report those to Atlassian.
The Daily Brew on this website runs in your browser, so its recipe can be read from the page. That's not a vulnerability; in the app, the recipe never leaves the server.
How Questlog is secured
- Built on Atlassian Forge. Questlog has no external servers and makes no external data egress calls. App data is kept in Forge-hosted storage within the customer's Atlassian environment.
- Read-only in Jira. Questlog's Jira permissions are read-only, so it cannot change issues.
- Checked on the server. XP, rewards and game actions are calculated and validated on the server, never trusted from the browser. Admin settings check the user's Jira admin permission.
- Data minimisation. Event payloads are trimmed to the fields the game needs. Questlog stores no Jira content: no comment text, issue titles, descriptions or attachments. See the data and privacy statement.
- Personal data reporting. Questlog reports stored account IDs to Atlassian at least every 7 days and erases closed accounts.
This website
questlog.umaylabs.com is a static website served over HTTPS. It has no accounts, forms, analytics or tracking cookies, and sends security headers including a Content Security Policy. Our security.txt lists the same contact details as this page.
Contact
Security reports: contact@umaylabs.com. For anything else, see Support.