Skip to content

Security and privacy

Mode: reference. How Tollgate handles your data, and where to find the binding legal documents.

Softwired Digital Pty Ltd publishes Tollgate. Security contact: help@softwired.com.au.

  • Runs on Atlassian.

    Tollgate is built entirely on Atlassian Forge. It runs on Atlassian-hosted infrastructure and stores all data in Atlassian’s hosted storage. In normal operation it makes no calls to any server operated by Softwired or a third party. No Softwired-hosted back end, database, or analytics system exists.

  • Shared-responsibility model.

    Atlassian secures the platform, runtime, storage, encryption, and tenant isolation. Softwired answers for the app’s code, its permission scopes, and how it uses the data it is granted.

  • Tenant isolation.

    Atlassian’s storage isolates each customer’s governance data. Tollgate reads and writes only within your own site.

  • No external AI.

    The Tollgate Rovo agent runs on Atlassian’s platform and answers from your own data, through read-only actions. Tollgate sends no governance data to any external AI service.

Tollgate stores the governance records you create in the app, plus the Jira (and, optionally, Confluence) data it reads to populate those surfaces. The records cover work packages and project status, the Business Case (also called the Investment Thesis), and the Risk register. They also cover decisions, scope changes, the audit trail, and app settings.

  • Atlassian site backups do not include app data.

    Atlassian’s backup and export tools cover Jira and Confluence content only. The platform excludes data held by Marketplace apps, Tollgate included. The same applies to third-party Jira backup products, site clones, and site-to-site migrations. Your Tollgate governance record does not travel with the site.

  • Atlassian stores the data durably.

    Tollgate’s data lives in Atlassian’s hosted storage. Atlassian replicates it across regions under its own disaster-recovery arrangements. Durability of the platform is Atlassian’s responsibility. A copy you control is yours.

  • Getting a copy.

    A full-record export is in rollout — watch the changelog. One workbook per project covers the business case, work packages, Risk register, decisions, changes, and audit trail. Until the export reaches your site, contact help@softwired.com.au to get your data out. See also getting your data out in the Help Centre.

  • Project deletion. Deleting a Jira project purges all of that project’s Tollgate data.

  • User deletion.

    Delete a user permanently from Jira and Tollgate scrubs their account identifier from per-project records. This is the right to be forgotten.

  • App uninstall.

    Uninstalling Tollgate purges the app’s data for the whole site immediately and permanently. Reinstalling does not bring it back. Export what you need before you uninstall.

The Atlassian Marketplace listing carries the Security Statement and Data Processing Agreement (DPA). The law of Queensland, Australia governs the EULA.