Trust Center

Where your data goes and how we protect it, for CogniRunner, Sentinel Vault, LeanZero Management and leanzero.net.

Last updated: October 4, 2026

Application Security

  • All three apps run on Atlassian Forge and store their data in Forge storage on your Atlassian site. Apart from the optional MCP demo servers a CogniRunner administrator can connect, we run no servers that receive app data.
  • Sentinel Vault and LeanZero Management carry Atlassian’s Runs on Atlassian badge: they send no data outside Atlassian. CogniRunner does not, because it can connect to AI providers, MCP servers and git hosts you choose.
  • Every connection uses HTTPS.
  • Keys you give an app are stored on your site, never in our source code. CogniRunner keeps AI provider keys, git tokens, webhook secrets and MCP server credentials in Forge’s encrypted secret storage. It stores no Atlassian deploy identity: a deploy pipeline reads FORGE_EMAIL and FORGE_API_TOKEN from secrets you add to your own repository.
  • Sentinel Vault’s source code is public under the Apache License 2.0. CogniRunner and LeanZero Management are commercial; their data flows and permissions are documented on their product pages.

Data Privacy

  • LeanZero SRL is registered in Romania and subject to the GDPR.
  • App data and each app’s backup live on your own Atlassian site. The backups survive an uninstall so you can restore your setup; the Privacy Policy says how to delete them.
  • Data residency: data in persistent Forge storage follows your site’s data residency where Atlassian supports it. Atlassian gives no residency commitment for app logs or Forge LLM requests, and data CogniRunner sends to a service you connect is outside it.
  • The apps send no analytics or telemetry to us. Atlassian shows us the apps’ operational logs, which can contain account IDs and short excerpts, unless your administrator turns log sharing off.
Full Privacy Policy

AI Data Processing

  • All three apps use Forge LLM by default, which runs Anthropic Claude models on Atlassian’s platform. The model call stays inside Atlassian. In CogniRunner, tools you turn on, such as MCP servers, web search and git, still reach their own services.
  • In CogniRunner your administrator can connect another AI provider with your own key. That provider then works under your agreement with it, not ours.
  • The AI advisors on our service pages use Anthropic, which does not train on API data. Each chat says it is an AI assistant.
  • We are the provider of these AI systems under the EU AI Act and say where AI is used. Outputs are probabilistic and can be wrong; review what matters.

Compliance

  • We are the controller for our website and services, and a processor for our app customers under our Data Processing Addendum.
  • Transfers outside the EEA rely on an adequacy decision or the European Commission’s Standard Contractual Clauses, except the two services the table below marks as having no agreement.
  • We follow Atlassian’s Security Bug Fix Policy for our cloud apps.
  • LeanZero SRL, CUI 51336260, EUID ROONRC.J2025012835002.
Data Processing Addendum

Sub-Processors

ProviderPurposeData ProcessedLocationTransfer safeguardUsed for
Atlassian (Forge platform, including Forge LLM)Hosts and runs our Marketplace apps, stores their data, and runs their AI features on Atlassian-hosted modelsThe Jira and Confluence content the apps work on, app configuration and logs, AI prompts and answersAtlassian's cloud infrastructure. Data in persistent Forge storage follows your site's data residency where Atlassian supports it; Atlassian gives no residency commitment for app logs or Forge LLM requestsAtlassian's data processing addendum (Standard Contractual Clauses) and its EU-U.S. Data Privacy Framework certificationMarketplace apps
Microsoft (Microsoft 365)Our business mailbox, office@leanzero.net: enquiries, quotes, support, security reports and privacy requestsName, email address, message content and attachmentsMicrosoft's cloud infrastructureMicrosoft's data protection addendum (Standard Contractual Clauses) and its EU-U.S. Data Privacy Framework certificationSupport; Website; LeanZero Link and MCP demo servers
Atlassian (Jira Service Management)Our support portal at leanzero.atlassian.netName, email address and the content of your requestAtlassian's cloud infrastructureAtlassian's data processing addendum (Standard Contractual Clauses) and its EU-U.S. Data Privacy Framework certificationSupport
Atlassian (our demo site)Hosts leanzero-demo.atlassian.net, where we create evaluator accounts and keep one private work item per evaluatorEmail address, name you set on the Atlassian account, Atlassian account ID, access datesAtlassian's cloud infrastructureAtlassian's data processing addendum (Standard Contractual Clauses) and its EU-U.S. Data Privacy Framework certificationWebsite
Amazon Web Services (Amplify, CloudFront, CloudWatch)Hosts leanzero.net and its server logsIP address, browser details, requested URLs, server log linesLondon (eu-west-2), plus CloudFront edge locations worldwideUnited Kingdom adequacy decision; AWS's data processing addendum (Standard Contractual Clauses) for edge locationsWebsite
PostHogWebsite analytics, and session replay if you accept analytics cookiesPseudonymous usage events, device and browser details, replays of pages viewedEU (Frankfurt)No transfer outside the EEAWebsite
ResendSends our emails (form receipts, keys, sign-in codes, newsletter) and holds the newsletter listEmail address, name if given, the content of the emailUnited StatesResend's data processing addendum (Standard Contractual Clauses) and its EU-U.S. Data Privacy Framework certificationWebsite; LeanZero Link and MCP demo servers
SanityContent platform for leanzero.net: comments, guest submissions, exam and demo key records, demo site access records, benchmark runsName and comment text, submission details, email addresses on key and demo access records, benchmark entriesEU (Belgium), with a worldwide content delivery network for published contentSanity's data processing addendum (Standard Contractual Clauses) where data leaves the EEAWebsite
AnthropicRuns the AI advisors on our service pages and drafts a summary of quote requestsYour chat messages and, for a quote request, your name, email, message, answers and the chatUnited StatesAnthropic's data processing addendum (Standard Contractual Clauses)Website
SerperWeb search: for the AI advisors, and for MCP Web Search demo keys used without your own Serper keySearch queries (the advisor writes them from your conversation to look up public facts)Not stated by SerperSerper publishes no data processing agreement; we have none in place with it. Queries are written to look up public facts, not about youWebsite; CogniRunner, only with our MCP demo servers
Z.AIOptional image text recognition in the MCP Doc Processor demo, when you use it without your own Z.AI keyThe images you send for text recognitionOutside the EEA (Z.AI does not state where)No adequacy decision and no data processing agreement in place; used only if you send images for recognitionCogniRunner, only with our MCP demo servers; LeanZero Link and MCP demo servers
CalendlyBooking a call with usName, email and the booking details you enterUnited StatesCalendly's data processing addendum (Standard Contractual Clauses) and its EU-U.S. Data Privacy Framework certificationWebsite
TailscaleNetwork access to our LeanZero Link sign-in service and our MCP demo serversIP address and connection metadata; Link device traffic is end-to-end encryptedTailscale's cloud infrastructureTailscale's data processing addendum (Standard Contractual Clauses)LeanZero Link and MCP demo servers; CogniRunner, only with our MCP demo servers

The “Used for” column shows what each provider serves. For our Marketplace apps that is Atlassian, the support tools (our mailbox and support portal), and, only if a CogniRunner administrator connects our MCP demo servers, Tailscale, Serper and Z.AI. AI providers, MCP servers and git hosts you connect to CogniRunner yourself are not our sub-processors.

Incident Response

  • Support and security response run 24 hours a day, every day.
  • Report vulnerabilities to office@leanzero.net or through the “Report a security vulnerability” form on our support portal. We acknowledge reports within 24 hours and offer safe harbor for good-faith research.
  • We fix vulnerabilities in our cloud apps within Atlassian’s timelines, counted from when they are reported or triaged: critical 10 days, high 4 weeks, medium 12 weeks, low 25 weeks.
  • If we discover or are told of an actual or suspected security incident, including a vulnerability or compromise of one of our apps, we notify Atlassian within 24 hours. If customer data in an app is affected, we notify the customer without undue delay and within 48 hours; as their processor, we leave notifying the authority to them. For data we control, we notify the supervisory authority within 72 hours where Article 33 GDPR applies.
  • We intend to join Atlassian’s Marketplace Security Bug Bounty Program; the policy page will link to it when we do.
Vulnerability Disclosure Policy

Documentation & Resources

Security & Privacy Contact

For security reports, privacy requests (including GDPR data subject rights), a countersigned DPA, or documentation not listed above, contact us any day of the week:

LeanZero SRL
Email: office@leanzero.net
Str. Toamnei 23 G, CAM. 1, Loc. Bragadiru, Jud. Ilfov, Cod 077025, Romania