Comprehensive Security & Governance Framework Overview

Comprehensive Security & Governance Framework Overview

 

IMPORTANT

Proprietary & confidential

This document is the sole property of LogicLemur Labs. Unauthorized distribution or reproduction is strictly prohibited. All policies contained herein are subject to modification at the sole discretion of the Management.


1. Information Security Policy (ISP)

Objective: To establish a robust framework for safeguarding the information assets of LogicLemur Labs while operating within the Atlassian Forge environment.

1.1. Core Philosophy
LogicLemur Labs adopts a "Reasonable Security Practices" approach as defined under Section 43A of the IT Act, 2000. Our security posture is primarily governed by the underlying security protocols of the Atlassian Cloud platform.

1.2. Scope
This policy applies to all employees, contractors, and third-party vendors associated with LogicLemur Labs.

1.3. Limitation of Liability
While LogicLemur Labs employs commercially reasonable efforts to secure its applications, users acknowledge that the application resides on third-party infrastructure (Atlassian). LogicLemur Labs shall not be held liable for security breaches originating from the platform provider's infrastructure.

1.4. Compliance
All personnel must adhere to these standards. Non-compliance may lead to disciplinary action, including termination and legal proceedings, at the sole discretion of the company.


2. Incident Response Plan (IRP)

Objective: To provide a structured method for detecting, reporting, and mitigating potential security incidents.

2.1. Definition of an Incident
An "Incident" is defined as any confirmed unauthorized access to LogicLemur Labs' operational metadata that results in a demonstrable impact on confidentiality or integrity.

2.2. Response Team (IRT)
The Incident Response Team is headed by the CTO/DPO. Their decision regarding the severity and remediation of an incident is final and binding.

2.3. Notification SLA
In the event of a significant breach of Sensitive Personal Data (as defined by Indian law), LogicLemur Labs will endeavor to notify affected parties within 72 business hours of the incident being internally confirmed and fully triaged. This timeline is subject to the cooperation of the platform provider (Atlassian).

2.4. Safe Harbor
LogicLemur Labs reserves the right to withhold notification if such disclosure would compromise ongoing investigations or national security interests.


3. Data Classification & Handling Policy

Objective: To categorize data based on sensitivity and define the appropriate handling requirements.

3.1. Classification Tiers

  • Public: Information intended for public consumption (e.g., Marketing materials).

  • Internal: Operational data (e.g., non-sensitive codebase).

  • Restricted: Rate-limit snapshots and configuration metadata.

  • Confidential: Access tokens and system credentials.

3.2. Data Residency
All application data is stored within the Atlassian Forge Key-Value Storage. LogicLemur Labs does not maintain independent persistent databases outside of the Atlassian environment, thereby ensuring that data residency follows the customer’s existing Jira regional settings.

3.3. Retention & Disposal
Data is retained only as long as necessary for functional requirements. Automated purging of activity logs occurs every 48 hours to ensure a minimal data footprint.


4. Secure SDLC & Coding Standards

Objective: To ensure security is integrated into every phase of the software development lifecycle.

4.1. Security by Design
LogicLemur Labs follows the principle of "Privacy by Design." We utilize TypeScript for type-safety and perform strict regex-based input validation on all user-controlled parameters.

4.2. Code Review & Testing

  • Peer Review: All code must undergo a mandatory security review prior to deployment.

  • Automated Scanning: We utilize SAST (Static Analysis) tools to detect vulnerabilities in the software supply chain.

  • Bug Bounty: We participate in the Atlassian VDP/Bug Bounty program to leverage external security expertise.

4.3. Third-Party Libraries
Only vetted and necessary npm packages are permitted. LogicLemur Labs disclaims liability for vulnerabilities found in third-party open-source libraries, although we will prioritize their remediation upon discovery.


5. Access Control Policy

Objective: To restrict access to LogicLemur Labs' systems and data to authorized personnel only.

5.1. Principle of Least Privilege (PoLP)
Access is granted on a "Need-to-Know" basis. Employees are only granted the minimum permissions necessary to perform their specific job functions.

5.2. Multi-Factor Authentication (MFA)
MFA is mandatory for all entry points, including the Atlassian Developer Console, GitHub, and internal administrative systems. No exceptions are permitted.

5.3. Termination of Access
Access to all systems shall be revoked immediately (within 24 hours) upon the resignation or termination of an employee.

5.4. Review Cycles
Access rights are reviewed quarterly. LogicLemur Labs reserves the right to revoke access at any time without prior notice if a security risk is perceived.


Approving Authority: Management, LogicLemur Labs
Effective Date: FEB 1, 2026