Atlassian Forge apps by AryonForge
AryonForge builds administration, governance and content apps for Jira, Confluence and Bitbucket Cloud. Every app runs entirely on the Atlassian Forge platform — inside Atlassian infrastructure, with no vendor-operated server, database or third-party analytics anywhere in the architecture.
Application code runs as Forge functions inside Atlassian’s runtime. Data at rest lives in Forge storage, which Atlassian hosts and secures.
Every app requests the narrowest scope set that makes its features work, and each scope is justified line by line on the app’s security page.
Most apps make no outbound call at all. Where one is required — the Atlassian Organization API, or a paired site’s web trigger — it is named in the manifest and explained on the app page.
Apps that can change access or delete content record what they did, who asked for it, and how to reverse it. Safe mode is the default wherever an action is destructive.
Customer content is never sold, rented, mined for advertising, or used to build profiles. There is no analytics endpoint to send it to.
Pre-release review findings, their reproduction steps, and the regression tests that close them are part of the public record for each app.
One viewer for every attachment on a Confluence page — with audit logging and SHA-256 integrity verification built in.
Per-project attachment rules for Jira — block or allow by extension, cap by size, exempt service accounts — with a monitor mode, a simulator, and a full audit trail.
Per-space attachment rules for Confluence — monitor first, then enforce — with an audit trail of what was removed and who changed the policy.
Continuously analyses every Confluence space, scores knowledge health, and remediates fourteen classes of problem in bulk — with a preview before anything is written and a full audit trail after.
Governed Confluence licence cleanup with a first-class, auditable ignore list — so you can prove automated cleanup did not remove access it shouldn’t have.
Finds inactive Jira seats, applies configurable deactivation policy, governs its own exception list, and produces enterprise-grade audit evidence — without ever deleting a user.
Finds inactive Bitbucket seats, explains exactly which grant keeps each one billable, and refuses to bulk-action anything that looks like CI.
Keeps issues synchronised between two independent Jira Cloud sites. The same app is installed on both; the two installations pair with each other and exchange changes directly. There is no hosted backend.
Targeted, scheduled announcements for Jira with per-reader acknowledgement tracking — publishable site-wide or by a project lead, without a site admin in the loop.
Targeted, scheduled announcements for Confluence with per-reader acknowledgement tracking — and a real page banner above page content.
Targeted, scheduled announcements for Bitbucket, published at workspace, project or repository level, with per-reader acknowledgement tracking.