Run the test drive: create a Jira-ready issue, review project fields and sources, then confirm the content boundary.
Roll out SecurePM with auditable checkpoints.
Use this checklist during evaluation and production rollout. Each step produces evidence your security team can file.
Prove the boundary before install.
Fetch /attestation, verify Ed25519 signature against pinned public key.
Confirm GET /api/privacy describes content-free licensing only.
Customer-owned Worker (Cloudflare path).
| Step | Action | Evidence |
|---|---|---|
| 1 | Deploy Worker to your Cloudflare account (Terraform or wrangler) | GET /healthz → auth: enforced |
| 2 | Set SHARED_SECRET (random, per install) | 401 on /draft without bearer |
| 3 | Configure model route (Workers AI, Bedrock, or AI Gateway) | GET /egress lists only that endpoint |
| 4 | Create D1 audit table + ingest sample sources | Audit row after first /draft |
| 5 | Confirm securepm.dev absent from egress allowlist | Screenshot or CI gate output |
Jira Cloud (Forge) or Data Center (Connect).
Install app, set Worker URL + shared secret + license key in project settings. Verify manifest egress allowlist includes your Worker host.
Upload Connect app, configure per clientKey in admin UI. Same wire contract as Forge — parity tested in CI.
Confirm custom fields load with allowed options (single-select, labels, number, cascading).
Production pilot on one project.
| Check | Pass criteria |
|---|---|
| Valid fields written | Summary, description (ADF), custom fields in one update |
| Invalid values rejected | UI shows rejected: not in allowed options; zero bad values in Jira changelog |
| Citations visible | Source ids linked in draft UI before apply |
| Audit row written | D1 row with actor, fields_set, warnings_text, compliance_action if applicable |
| Failure UX | Worker down → explicit unreachable message, not a hung spinner |
When Cloudflare is not acceptable.
Python/FastAPI in your VPC. docker run --network none verified healthy with zero egress.
Ed25519-signed license file; same canonical wire as Worker attestation.
Optional audit export to customer SIEM URL (validated, soft-fail on network error).
Architecture workshop for Business and Enterprise.
We walk through schema mapping, model routing, and audit export with your platform and compliance leads.