Procurement & vendor security
This page collects the answers reviewers most often need when evaluating Exportelier.
Data flow summary
- The main app reads Jira data and renders documents on Forge. It makes no external calls and stores no document content.
- The optional Automation app performs outbound delivery (email, Slack incoming webhooks, Microsoft Teams Workflows and API) with SSRF protection and provider-specific secret URLs.
- An append-only audit log records export and admin events as metadata only. See Audit log.
Sub-processors
The main app introduces no third-party rendering services. Delivery in the Automation app reaches only the destinations you configure.
Certifications and roadmap
The path to Cloud Fortified certification is on the roadmap — see Release notes.
Common questionnaire answers
- Does data leave Atlassian? Not from the main app. See Data residency.
- Are documents stored? No — they are streamed and deleted. See Data retention & GDPR.
- Is activity auditable? Yes — see Audit log.
Keep this current
Treat this page as a living document; update it as certifications and sub-processor details evolve.