LT.Solutions Security Centre
Security is part of the architecture of every LT.Solutions product. Customer data stays inside the platforms needed to deliver the service, and LT.Solutions infrastructure only enters the data path where the product architecture requires it.
The products use different architectures, so the security boundary is documented separately for each one. Choose a product below and read its own boundary, permissions and evidence status.
- VerifiedConfirmed against the deployed production environment.
- ImplementedConfirmed in the application code or configuration, not yet confirmed against production.
- ProposedA documented design. Not represented as an operating security control.
- InheritedSupplied by the platform, not implemented by us. Can also be verified.
Grouped by where the code actually runs. That one fact changes every other answer on this page, so it orders the list ahead of product family.
LaunchPad
A Forge application for Jira Service Management. It runs inside Atlassian Cloud on the Node.js 22 Forge runtime, on infrastructure Atlassian operates and secures. There is no LT.Solutions server in the data path.
Jira and Assets data.
- Issues and projects
- Users
- Service desk requests and request types
- Screen, screen tab and screen scheme setup
- Assets: schemas, object types, attributes, objects, configuration and icons
Nothing on our side.
- Application configuration, in Forge storage
- Job state, in Forge storage
Both sit in Forge storage tied to your installation. LT.Solutions holds no separate copy.
One address, and it is Atlassian’s own.
- api.atlassian.com
Forge blocks any domain not on that list. There is no LT.Solutions endpoint and no third party service on it.
The Jira and Assets content it builds for you.
- Issues
- Service desk requests and request types
- Project and Jira configuration
- Assets schemas, object types, attributes, objects and configuration
It also holds the Assets import configuration permission, used by its import and export features.
We ask you for no credential at all.
- Reaches Jira and Assets through the Forge gateway
- Uses Atlassian’s own authentication
- Licensing enforced through Forge
It builds things on your behalf.
- Jira Service Management request forms
- Assets schemas
That is the product’s function, and it cannot be delivered with read access alone.
The configuration and project management scopes are required because LaunchPad builds Jira Service Management request forms and Assets schemas on the customer’s behalf.
- No LT.Solutions server sits in the data path.
- LaunchPad declares no Assets deletion scope.
- No third party service appears in its permitted external domains.
Implemented, confirmed against the production Forge manifest. Platform execution, storage encryption and egress enforcement are inherited from Atlassian Forge.
Product security overview
Architectural boundaries, side by sideThe table describes architectural boundaries. It is not a claim that every product handles the same data or holds the same permissions. Each product declares only the permissions, external systems and storage its own operation requires.
CSA CAIQ v4.1, ready for review
A completed Consensus Assessment Initiative Questionnaire for our Forge applications. It is the document most security teams start from, so take it straight into a review. Nothing to ask for and nobody to wait on.
No form and no email needed. For anything the assessment does not answer, write to security@lt.solutions and we usually reply within two working days.
Found something? Tell us directly.
Include the affected product, the behaviour you saw, reproduction steps where you have them, and enough detail for us to investigate. We ask researchers not to access customer data, disrupt services or run destructive testing.
security@lt.solutionsReviewers can ask us anything on this page.
Customers and Marketplace reviewers can contact us for more detail on application permissions, data flows, subprocessors, hosting or product specific controls.