Effective Date: June 1, 2026
At Baseliner.ai, we recognize that security is paramount to our users, particularly when integrating project status reporting solutions within the Atlassian ecosystem. This Security Policy outlines our rigorous commitment to maintaining the confidentiality, integrity, and availability of your data, establishing the protocols we employ to secure our web application, infrastructure, and associated systems.
1. Security Incident Handling & Response
Baseliner.ai maintains a structured Incident Response Plan (IRP) designed to identify, contain, and mitigate potential security threats swiftly. Our incident handling methodology follows a standardized lifecycle:
- Identification & Detection: Continuous automated alerting mechanisms and internal auditing tools monitor system anomalies and potential unauthorized access vectors.
- Containment: Upon detecting a validated threat, our security team initiates immediate containment protocols to isolate affected systems, limiting potential impact while maintaining core system integrity.
- Eradication & Recovery: The root cause of the incident is analyzed, eliminated, and systems are verified as secure before returning to baseline operations.
- Notification & Compliance: In the event of a confirmed data breach impacting customer data, Baseliner.ai will notify affected users and relevant compliance authorities within 72 hours of verification, providing clear insights into the nature of the breach and mitigation steps taken.
2. Vulnerability Management Process
We proactively identify and remediate security vulnerabilities to protect our systems from emerging exploits. Our vulnerability management workflow includes:
2.1 Reporting
We welcome responsible disclosure from security researchers, partners, and customers. Vulnerabilities can be securely submitted to our security team via email at info@baseliner.ai. Submissions should include clear replication steps and technical context to aid our investigation.
2.2 Triage
Upon receipt, all reports are triaged within 48 business hours. We assess risk based on the Common Vulnerability Scoring System (CVSS) framework, considering exploitability, data impact, and scope.
2.3 Remediation SLAs
Baseliner.ai adheres to strict Service Level Agreements (SLAs) for deploying security patches based on threat severity:
| Severity Level |
CVSS Score Range |
Remediation Window |
| Critical |
9.0 – 10.0 |
Within 48 Hours |
| High |
7.0 – 8.9 |
Within 14 Days |
| Medium |
4.0 – 6.9 |
Within 30 Days |
| Low |
0.1 – 3.9 |
Best Effort / Next Release Cycle |
4. Questions and Policy Review
This security policy is reviewed at a minimum annually to address evolving compliance mandates and system updates. For specific inquiries regarding our security framework or infrastructure configuration, please reach out to our dedicated operations desk at info@baseliner.ai.