Sovereign World Labs

Security & responsible disclosure

A clear route for reporting vulnerabilities in our products and public services.

Effective and last updated: 4 September 2026

Report a security issue

Email security@sovereignworldlabs.com with the affected product or URL, potential impact, safe reproduction steps, timestamps, and your preferred contact details.

Please do not include customer data, credentials, access tokens, or destructive proof. Do not test against systems or Atlassian sites you do not own or have explicit permission to assess.

What to expect

We aim to acknowledge credible reports promptly, validate and assess severity, contain active risk, prepare and verify remediation, coordinate disclosure where appropriate, and communicate material customer impact responsibly.

Safe-harbour intent

We support good-faith research that avoids privacy violations, service disruption, social engineering, persistence, data extraction, and access beyond the minimum needed to demonstrate an issue. This page does not authorize testing of Atlassian infrastructure or third-party services.

ReplyTurn security posture

  • Runs entirely on Atlassian Forge.
  • No external backend, Remote, analytics, advertising, or customer-data egress.
  • No persisted comment bodies.
  • Tenant-isolated hosted storage and least-privilege Jira permissions.
  • Machine-safe operational logging designed to exclude customer content and personal identifiers.

Product support

For configuration questions and ordinary defects, use support@sovereignworldlabs.com.