Security

Security and data handling

Where each app runs, what it stores and what access it needs. Share this page with whoever approves new vendors at your company.

By app

Where each app runs and what it stores

Where a platform lets us run the app on its own hosting, we do. Your data then stays with a vendor you have already approved.

License Audit for JiraRuns on Atlassian Forge, inside Atlassian's cloud and your site's data region. Read-only permissions. Stores scan progress and, for each inactive user, an account ID and how long they've been inactive. No names or emails are stored.
License Audit for ConfluenceRuns on Atlassian Forge, on the same terms. Read-only permissions for the user list and content search. No API key or token is created.
Time in Status + SLARuns on monday code, monday.com's own hosting. Stores board, item and column IDs, status labels and times. No item names, people or emails. No long-term access token is stored.
Tallyo: Stocktake & CountsHosted by us. Reads products, locations and stock levels, and stores counts and their history. No access to orders or customers.
Ticket PDF & AttachmentsRuns inside Zendesk. Zendesk hosts the app; there is no TELCOMA server. Reads the open ticket with the agent's own access. Stores nothing and sends nothing to us.
Form Options SyncRuns in your own Google account as an Apps Script add-on. Accesses only the current form and the sheet you link. Stores counts per option, never form answers. Only your email address is sent to us, to check your plan.

Practices

Rules that apply to every app

Minimum access

Each app asks only for the permissions it needs. Our reporting apps have no write access at all.

Minimum data

We store IDs and dates instead of names wherever we can.

Secrets kept out of code

Keys are held in the platform's secret store and never written to logs. Logs contain IDs, counts and errors only.

Input checking

Every request is validated, and platform APIs are called with parameters, never with strings built from input.

Safe deletion

Where an app can remove data, it needs a checked copy first, runs as a preview by default, and can be stopped with one switch.

Data removed on uninstall

When you uninstall, your account's data is deleted. We confirm in writing on request.

Reporting an issue

Found a security problem?

Email support@telcomaglobal.com with "security" in the subject. Tell us what you found and how to reproduce it.

  • We confirm receipt within one business day.
  • We send our assessment and a fix date within five business days.
  • We won't take legal action over good-faith research that doesn't harm customers or access their data.
  • Please don't publish it until we've released a fix.

If an incident affects your data, we will tell you directly.

Vendor
TELCOMA Technologies Private Limited
In business since
2009
Registered office
Ludhiana, Punjab, India
Security contact
support@telcomaglobal.com
Data processing agreement
Available on request
Sub-processors
Listed in each app's privacy policy

Send us your security questionnaire and we'll complete it.