Cost Slasher security policy
LeanZero SRL operates Cost Slasher's Forge application and external AWS recovery service. This policy describes implemented safeguards and the channel for security concerns; it is not a compliance certificate.
Updated 4 October 2026
Report a security concern
Contact office@leanzero.net with the subject “Cost Slasher security”. Include the affected app version, a non-secret reference, steps to reproduce and the impact you observed. If a report needs sensitive evidence, first ask for an appropriate transfer channel. Do not email organisation API keys, OAuth tokens, session cookies, signatures or unredacted personal exports.
Test only an installation you are authorised to assess. Avoid disruption, other accounts' data and access changes. A report does not grant permission to probe another organisation. LeanZero coordinates verified security incidents with affected customers and Atlassian through the applicable incident process.
For general product questions, problems and feature requests, use the Cost Slasher support portal. Report sensitive security details through the email channel above before including them in a support ticket.
Account and action authority
Native identity comes from Atlassian's Forge context. Recovery identity comes from Atlassian's read:me OAuth flow and is bound to a company session. Opening recovery or signing in grants no licence. Current own-account identity, installation and site binding, eligibility and scoped app permissions are checked separately.
REST credentials are issued by the app with explicit scopes and issuer checks. They are not an unrestricted administrator bypass. Sensitive actions retain original request references and versions; lost responses remain uncertain until the original outcome is verified. Protected returns and unresolved provider effects keep their capacity obligations.
Credentials and encryption
An organisation Admin API key is required for configured organisation-management APIs. It is stored in the Forge installation's encrypted secret vault. Recovery does not receive it. Pairing and notification shared secrets are stored in Forge secret storage and AWS Secrets Manager for their respective signed connections.
Normal recovery users grant read:me only. Their access token is used server-side to read identity and is not persisted. A separate publisher-only read:me and offline_access grant supports Atlassian personal-data reporting; its refresh token is encrypted in AWS Secrets Manager.
Forge business records use Atlassian-managed storage encryption; immutable audit, usage and history archive payloads use Forge encrypted secret storage. External DynamoDB records, secrets, failed-event queues and CloudWatch log groups use AWS encryption at rest. AWS KMS protects the configured Ireland-origin data stores. Recovery traffic uses HTTPS, TLS 1.2 or later at the configured external edge and origin, and HSTS.
Recovery and browser safeguards
Recovery cookies are Secure, HttpOnly and SameSite. Browser mutations require the correct origin and CSRF token. OAuth state is single use and browser bound. Signed installation requests have exact audience, method, path, generation, expiry and replay checks. API and authentication responses are not cached; public recovery pages disallow framing.
Technical diagnostics use fixed messages, approved codes, counts and statement hashes. Gateway access logs omit raw URLs, queries, headers, cookies and bodies. Business audit records intentionally contain scoped account and action references, but exclude credentials and raw personal provider responses. Necessary delivery data can remain in encrypted failed-event storage.
Lifecycle and verification limits
The privacy statement lists retention and external providers. The Data Processing Addendum sets LeanZero's customer-processing obligations, including breach assistance, audits and return or deletion. Expiry is not an immediate physical-deletion guarantee. Uninstalling does not settle unresolved work or automatically erase external registry records. Privacy or shutdown requests need their own verified completion; unresolved work alone does not authorise indefinite retention.
Source checks, dependency scans and local browser tests are separate from deployed acceptance. Each installation's storage approval is bound to its current qualification source, schema and strategy. Ordinary-user recovery, provider effects and workload limits require additional current proof. Automatic release remains off until required recovery, warning, activity and capacity checks pass.
This policy does not claim ISO 27001, SOC 2, HIPAA, FedRAMP, a completed CAIQ Lite, Cloud Fortified status or Runs on Atlassian eligibility for Cost Slasher. Any future accreditation must be identified separately with its actual scope and evidence.