SecurePM
Deployment checklist

Roll out SecurePM with auditable checkpoints.

Use this checklist during evaluation and production rollout. Each step produces evidence your security team can file.

Week 0 — Evaluate

Prove the boundary before install.

☐ Browser test drive

Run the test drive: create a Jira-ready issue, review project fields and sources, then confirm the content boundary.

☐ Attestation verify

Fetch /attestation, verify Ed25519 signature against pinned public key.

☐ License boundary

Confirm GET /api/privacy describes content-free licensing only.

Week 1 — Deploy data plane

Customer-owned Worker (Cloudflare path).

StepActionEvidence
1Deploy Worker to your Cloudflare account (Terraform or wrangler)GET /healthz → auth: enforced
2Set SHARED_SECRET (random, per install)401 on /draft without bearer
3Configure model route (Workers AI, Bedrock, or AI Gateway)GET /egress lists only that endpoint
4Create D1 audit table + ingest sample sourcesAudit row after first /draft
5Confirm securepm.dev absent from egress allowlistScreenshot or CI gate output
Week 2 — Connect front-end

Jira Cloud (Forge) or Data Center (Connect).

Forge Cloud

Install app, set Worker URL + shared secret + license key in project settings. Verify manifest egress allowlist includes your Worker host.

Data Center

Upload Connect app, configure per clientKey in admin UI. Same wire contract as Forge — parity tested in CI.

Schema read

Confirm custom fields load with allowed options (single-select, labels, number, cascading).

Week 3 — Validate writeback

Production pilot on one project.

CheckPass criteria
Valid fields writtenSummary, description (ADF), custom fields in one update
Invalid values rejectedUI shows rejected: not in allowed options; zero bad values in Jira changelog
Citations visibleSource ids linked in draft UI before apply
Audit row writtenD1 row with actor, fields_set, warnings_text, compliance_action if applicable
Failure UXWorker down → explicit unreachable message, not a hung spinner
Enterprise — Air-gap path

When Cloudflare is not acceptable.

Reference backend

Python/FastAPI in your VPC. docker run --network none verified healthy with zero egress.

Offline license

Ed25519-signed license file; same canonical wire as Worker attestation.

SIEM webhook

Optional audit export to customer SIEM URL (validated, soft-fail on network error).

Need help?

Architecture workshop for Business and Enterprise.

We walk through schema mapping, model routing, and audit export with your platform and compliance leads.

Book workshop