# Security Policy | Optimizory

---

Security Policy

# Optimizory Information Security Policy

## 1\. Purpose

The purpose of this policy is to protect the confidentiality, integrity, and availability of information managed by Optimizory and its products, including cloud-hosted and on-premise solutions. It defines how we secure customer data, internal systems, and development practices, ensuring the trust of our users and compliance with industry standards.

## 2\. Scope

This policy applies to:

-   All employees, contractors, and consultants at Optimizory, regardless of location
-   All systems, infrastructure, and codebases used to develop, operate, and support Optimizory products
-   All environments—whether customer-hosted, Optimizory-hosted (e.g., vREST on AWS), or third-party platforms (e.g., Atlassian, monday.com)

## 3\. Core Principles

Optimizory follows the **CIA triad** for information security:

-   **Confidentiality** – Protecting information from unauthorized access
-   **Integrity** – Ensuring data is accurate and unaltered
-   **Availability** – Ensuring systems and data are accessible to authorized users when needed

## 4\. Security Commitments

Optimizory is committed to the following:

-   Implementing **role-based access control** for all systems
-   Maintaining **secure software development practices**, including code reviews and vulnerability scanning
-   Regularly **reviewing and updating infrastructure**, especially cloud environments
-   **For apps - Links Explorer, Pact, Baseline X, Report X, and Custom ID:** We do not store any personal or issue data on our servers. All data processed by the app remains strictly within the customer's Jira instance.
-   Monitoring systems for unusual activity and **responding promptly to security incidents**
-   Providing **security awareness training** to all team members
-   Keeping business continuity and disaster recovery plans up-to-date
-   Reviewing this policy annually or when major changes occur

## 5\. Compliance and Standards

Optimizory strives to align with globally recognized standards and good practices, including:

-   ISO/IEC 2700
-   ISO 9001
-   Atlassian and monday.com security guidelines
-   Indian data protection laws and other applicable regional requirements

## 6\. Responsibilities

-   **Management** is responsible for ensuring that security objectives align with company strategy and are implemented effectively
-   **Engineering and DevOps teams** are responsible for secure software development and infrastructure maintenance
-   **All employees** are responsible for protecting credentials, reporting incidents, and following secure data handling practices

## 7\. Incident Reporting

Any employee or contractor who notices suspicious behavior, security vulnerabilities, or breaches must report them immediately to the designated security contact at Optimizory: [support@optimizory.com](mailto:support@optimizory.com)

## 8\. Review and Updates

This policy will be reviewed annually or as needed to reflect operational, legal, or technological changes.

## Our Products Portfolio

[](/links-explorer.html)

[](/links-explorer.html)

[

![Links-explorer Jira](/assets/img/lxp-monday-logo.webp)

#### Links Explorer for Jira

The #1 user-rated Traceability app for Jira.

](/links-explorer.html)[Read more](/links-explorer.html)

[](/rmsis.html)

[](/rmsis.html)

[

![RMsis](/assets/img/logos/rmsis/png/rmsis-3.webp)

#### RMsis

Most mature requirements management application for Jira.

](/rmsis.html)[Read more](/rmsis.html)

[](/pact.html)

[](/pact.html)

[

![PACT](./assets/img/pact-screenshots/pact-logo-1.png)

#### PACT

Your dedicated solution for efficient Contract Lifecycle Management.

](/pact.html)[Read more](/pact.html)

[](/baseline-x.html)

[](/baseline-x.html)

[

![BaselineX](/assets/img/baseline-x/baseline-x.jpg)

#### Baseline X

The ultimate tool to take issue snapshots and track changes

](/baseline-x.html)[Read more](/baseline-x.html)

[](/report-x.html)

[](/report-x.html)

[

![ReportX](/assets/img/report-x/report-x.png)

#### Report X

A Complete Traceability and Reporting Solution for Jira

](/report-x.html)[Read more](/report-x.html)

[](/customid.html)

[](/customid.html)

[

![CustomID](/assets/img/custom-id/custom-id.png)

#### Custom ID

Make your JIRA issue IDs more informative

](/customid.html)[Read more](/customid.html)

[](/rmview.html)

[](/rmview.html)

[

![RMview](/assets/img/logos/rmview/rmview.png)

#### RMview

Simplify Your Requirement Management

](/rmview.html)[Read more](/rmview.html)

[](/unifieddocs.html)

[](/unifieddocs.html)

[

![unifieddocs](/assets/img/unifieddocs/unifiedlogo.png)

#### UnifiedDocs

Dynamic Documentation for Confluence

](/unifieddocs.html)[Read more](/unifieddocs.html)

[](/risk-manager.html)

[](/risk-manager.html)

[

![unifieddocs](/assets/img/logos/risk-manager/risk-manager-logo.png)

#### Risk Manager

Risk Clarity For Everyone - Right Inside Jira

](/risk-manager.html)[Read more](/risk-manager.html)

[](https://vrest.io/)

[](https://vrest.io/)

[

![vRest](./assets/img/logos/vrest/all/png/green/logo_green.webp)

#### vREST

Record, Specify, Test and Mock your RESTful and Other Web APIs.

](https://vrest.io/)[Read more](https://vrest.io/)

[](/monday/links-explorer-product/index.html)

[](/monday/links-explorer-product/index.html)

[

![Links-explorer Monday](/assets/img/lxp-monday-logo.webp)

#### Links Explorer for monday

Get end-to-end traceability via tree view of item links.

](/monday/links-explorer-product/index.html)[Read more](/monday/links-explorer-product/index.html)

### Have any queries?

Please send a mail to [support@optimizory.com](mailto:support@optimizory.com) to get in touch with us.

We use cookies to improve your experience and analyze usage. For details or to change your preferences, see our [Privacy Policy](/privacy-policy.html). By clicking “Accept and Proceed” or continuing to browse, you consent to our use of cookies.

Accept and Proceed