...
- We will investigate as soon as we can and write an internal report,
- If we confirm the vulnerability, we will notify Atlassian,
- If a breach allowed access or alteration of customer data, we also notify our GDPR authorities within 72hrs (namely CNIL, for France),
- If a breach allowed access or alteration of customer data by an external person, we also notify those customers directly.
- If a breach only allowed two users of the same customer to view/edit data edit data they were not permitted to (permission violation), we choose whether we only notify customers through the release notes when delivering the new version, or whether we directly contact customers.
...