Security policy

Last updated: 25 August 2026

This policy describes the technical and organizational measures Crosstown Tech uses to protect customer data in QuickBooks Timesheet Sync for Jira & Tempo ("the app") and in the systems that support it. It is the vendor security policy for this app; Privacy covers what data the app reads, writes and stores.

1. Architecture and hosting

2. Encryption

3. Authentication and authorization

4. Tenant isolation

Every stored record is keyed to the Jira installation that created it, and no query crosses that boundary. One customer cannot reach another customer's data through the application. Jira reads run as the identity of the person who connected QuickBooks, so the app never sees issues that person cannot see, and the per-issue panel returns nothing without a user token.

5. Data minimization

The app stores no personal data: people are recorded only by their Atlassian account id, and no name or email address is written down — not for your Jira users, and not for your QuickBooks employees. Names are fetched live when a screen is drawn and then discarded. The app stores no QuickBooks financial records, invoices, bank or payroll data. What is stored, and for how long, is listed in full on the privacy page.

6. Internal access control

7. Secure development

8. Credential lifecycle

9. Logging and monitoring

10. Vulnerability management

11. Reporting a vulnerability

We welcome reports from customers and security researchers. Email security@crosstowntech.com (or support@crosstowntech.com) with enough detail to reproduce the issue. We will acknowledge within 2 business days and keep you updated until it is resolved. Please do not publicly disclose an unpatched issue, and please do not test against another customer's data — we will not pursue action against researchers who follow this.

12. Incident response

If we become aware of a security incident affecting customer data:

To date, Crosstown Tech has had no known security breach affecting customer data.

13. Availability and continuity

Availability, redundancy and backups are provided by the underlying platforms — Atlassian Forge for the user interface and Convex Cloud for the backend and database. The app is not on the critical path for either Jira or QuickBooks: if syncing is interrupted, worklogs stay in Jira and time activities already written stay in QuickBooks, and the app reconciles when it resumes. Nothing is lost by an outage.

14. Sub-processors

No data is sold, shared with advertisers, or used to train models.

15. Compliance

16. Changes to this policy

We update this policy as the app changes. Material changes are reflected here with a new "last updated" date.

17. Contact

Security reports: security@crosstowntech.com. General support: support@crosstowntech.com or the support portal. Please include your Jira site URL.