Trust · Security

LT.Solutions Security Centre

Security is part of the architecture of every LT.Solutions product. Customer data stays inside the platforms needed to deliver the service, and LT.Solutions infrastructure only enters the data path where the product architecture requires it.

The products use different architectures, so the security boundary is documented separately for each one. Choose a product below and read its own boundary, permissions and evidence status.

How to read this page
  • VerifiedConfirmed against the deployed production environment.
  • ImplementedConfirmed in the application code or configuration, not yet confirmed against production.
  • ProposedA documented design. Not represented as an operating security control.
  • InheritedSupplied by the platform, not implemented by us. Can also be verified.
Runs entirely inside AtlassianNo server of ours touches your data.
Runs partly on servers we operateSome of your data passes through us.
Not documented yetNot in production, so we claim nothing.

Grouped by where the code actually runs. That one fact changes every other answer on this page, so it orders the list ahead of product family.

LaunchPad

Where you can get itLive on the Atlassian Marketplace
How far the security claims are checkedImplemented

A Forge application for Jira Service Management. It runs inside Atlassian Cloud on the Node.js 22 Forge runtime, on infrastructure Atlassian operates and secures. There is no LT.Solutions server in the data path.

What it reads

Jira and Assets data.

  • Issues and projects
  • Users
  • Service desk requests and request types
  • Screen, screen tab and screen scheme setup
  • Assets: schemas, object types, attributes, objects, configuration and icons
What it stores

Nothing on our side.

  • Application configuration, in Forge storage
  • Job state, in Forge storage

Both sit in Forge storage tied to your installation. LT.Solutions holds no separate copy.

External endpoints

One address, and it is Atlassian’s own.

  • api.atlassian.com

Forge blocks any domain not on that list. There is no LT.Solutions endpoint and no third party service on it.

What it writes

The Jira and Assets content it builds for you.

  • Issues
  • Service desk requests and request types
  • Project and Jira configuration
  • Assets schemas, object types, attributes, objects and configuration

It also holds the Assets import configuration permission, used by its import and export features.

Authentication

We ask you for no credential at all.

  • Reaches Jira and Assets through the Forge gateway
  • Uses Atlassian’s own authentication
  • Licensing enforced through Forge
Why it needs write access

It builds things on your behalf.

  • Jira Service Management request forms
  • Assets schemas

That is the product’s function, and it cannot be delivered with read access alone.

Declared permissions27 Forge scopes
Application storage
storage:app
Jira and Jira Service Management
read:jira-workwrite:jira-workread:jira-usermanage:jira-projectmanage:jira-configurationread:servicedesk-requestwrite:servicedesk-requestread:requesttype:jira-service-managementwrite:requesttype:jira-service-managementread:servicedesk:jira-service-managementread:issue-type-screen-scheme:jiraread:screen-scheme:jiraread:screen:jiraread:screen-tab:jira
Assets
read:cmdb-schema:jirawrite:cmdb-schema:jiraread:cmdb-type:jirawrite:cmdb-type:jiraread:cmdb-attribute:jirawrite:cmdb-attribute:jiraread:cmdb-object:jirawrite:cmdb-object:jiraread:cmdb-config:jirawrite:cmdb-config:jiraread:cmdb-icon:jiraimport:import-configuration:cmdb

The configuration and project management scopes are required because LaunchPad builds Jira Service Management request forms and Assets schemas on the customer’s behalf.

Boundaries it does not cross
  • No LT.Solutions server sits in the data path.
  • LaunchPad declares no Assets deletion scope.
  • No third party service appears in its permitted external domains.
Evidence

Implemented, confirmed against the production Forge manifest. Platform execution, storage encryption and egress enforcement are inherited from Atlassian Forge.

Product security overview

Architectural boundaries, side by side
Product
Platform
Do our servers touch your data
External endpoints
Where you can get it
LaunchPad
Atlassian Forge
No
api.atlassian.com
Live on the Atlassian Marketplace
Second Chance
Atlassian Forge
No
None
Live on the Atlassian Marketplace
LT Census Connect
Atlassian Forge
No
Apple Business Manager and Kandji
Preparing for release, in Atlassian Marketplace review
Asset Sync
Google Workspace and Atlassian Cloud
Yes, for sign in and the sync service
Published before release
Preparing for release
LT Census Discovery
External discovery engine with Atlassian integration
Answered once it is live
Published when verified
Preparing for release

The table describes architectural boundaries. It is not a claim that every product handles the same data or holds the same permissions. Each product declares only the permissions, external systems and storage its own operation requires.

Documentation

CSA CAIQ v4.1, ready for review

A completed Consensus Assessment Initiative Questionnaire for our Forge applications. It is the document most security teams start from, so take it straight into a review. Nothing to ask for and nobody to wait on.

283
Controls answered
17
Security domains
LT.Solutions Forge applications, CAIQ v4.1
Covers LaunchPad and Second Chance. 72 pages, 1.2 MB.
Download

No form and no email needed. For anything the assessment does not answer, write to security@lt.solutions and we usually reply within two working days.

Vulnerability reporting

Found something? Tell us directly.

Include the affected product, the behaviour you saw, reproduction steps where you have them, and enough detail for us to investigate. We ask researchers not to access customer data, disrupt services or run destructive testing.

security@lt.solutions
Questions about product security

Reviewers can ask us anything on this page.

Customers and Marketplace reviewers can contact us for more detail on application permissions, data flows, subprocessors, hosting or product specific controls.

We use analytics cookies to understand how the site is used, only if you accept. Read our privacy policy.