Skip to main content

Terms of Service

Last updated: 2026-05-31


1. Parties and acceptance

These Terms of Service ("Terms") constitute a legal agreement between:

  • Ilgiz Khusnullin, an individual based in Ulm, Germany, trading as Attestsys ("Attestsys", "we", "us", "our") — the operator of the Attestsys suite of Jira apps
  • You — the Jira workspace administrator or organisation that installs and uses the Attestsys apps ("Customer", "you", "your")

By installing an Attestsys app from the Atlassian Marketplace or accessing any Attestsys service, you agree to these Terms. If you are accepting on behalf of an organisation, you represent that you have authority to bind that organisation.

These Terms supplement and do not replace the Atlassian Marketplace Terms of Use and the Atlassian Customer Agreement, which govern your relationship with Atlassian. In the event of conflict between these Terms and Atlassian's terms, Atlassian's terms take precedence with respect to the Atlassian platform.

Where the Attestsys apps are distributed under the Atlassian Marketplace Standard End User Agreement (Bonterms v1.0), our Additional Terms serve as the Provider-Specific Terms supplement and take precedence over the Standard Agreement where they conflict.


2. Description of service

Attestsys provides apps for the Atlassian Jira platform that create cryptographically-signed, tamper-evident, independently verifiable records of Jira activity:

  • Tamper-Evident Audit Log for Jira — signs and hash-chains Jira event records using ECDSA P-256 (RFC 6979 deterministic) and RFC 3161 trusted timestamping.

Additional Attestsys apps (GitHub Evidence Pack for Jira; Signed Approvals for Jira) are in development and will be governed by these Terms once published on the Atlassian Marketplace.

The apps are published on the Atlassian Marketplace and operate as Forge Remote apps. Event data from your Jira workspace is transmitted to and processed on Attestsys backend infrastructure hosted on Hetzner Cloud in Nuremberg, Germany (EU).


3. Editions and subscription

3.1 Free tier

The Tamper-Evident Audit Log is available on a free tier with the following limitations:

  • Audit chain retention: 30 days
  • Evidence bundle exports: 10 per calendar month
  • Timestamping: independent public RFC 3161 timestamp authorities (non-qualified per-event timestamps, clearly labelled); EU Trusted List QTSP for paid-tier qualified checkpoints

The free tier is provided without charge and without any service level commitments. We reserve the right to modify free tier limits at any time with 30 days' notice.

3.2 Paid tiers

Paid editions (Standard, Advanced, Enterprise) are in development and will be available through the Atlassian Marketplace once released. Enterprise contracts (Paid via Vendor) require prior written agreement with Attestsys. Pricing, features, and billing terms for paid editions are set out in the Atlassian Marketplace listing and in any order form or Enterprise contract.

3.3 Billing via Atlassian Marketplace

For apps purchased through the Atlassian Marketplace, billing is managed entirely by Atlassian. Atlassian's billing terms, refund policies, and subscription management apply. We do not collect or process payment information for Marketplace-billed subscriptions.


4. Acceptable use

You may use the Attestsys apps only for lawful purposes and in accordance with these Terms. You agree not to:

  • Use the apps to process data you do not have the right to process
  • Attempt to tamper with, circumvent, or reverse-engineer the cryptographic audit chain
  • Use the apps to create false or fraudulent audit records
  • Interfere with or disrupt the Attestsys backend service or infrastructure
  • Exceed any usage limits applicable to your edition in bad faith
  • Resell or sublicense access to the Attestsys service without our written consent

We reserve the right to suspend or terminate access to the service for material breach of these Terms.


5. Data processing

5.1 Your data

You retain all rights to data you process through the Attestsys apps. We process your data solely to provide the service described in these Terms and our Data Processing Agreement (DPA).

5.2 Data Processing Agreement

As a data processor acting on your behalf, we are bound by the Data Processing Agreement incorporated into these Terms by reference. The DPA sets out the subject matter, nature, purpose, and duration of processing, the types of personal data and categories of data subjects, and our obligations and rights as processor.

5.3 Data residency

All data is processed and stored exclusively on Hetzner Cloud infrastructure in Nuremberg, Germany (EU). We do not transfer your data outside the EEA. See the Privacy Policy and Security Statement for full details.


6. Cryptographic records

The Attestsys audit chain creates tamper-evident, independently verifiable records of workflow activity. We do not warrant any particular outcome from using these records — their meaning and usefulness in any given context is determined by you and the people you share them with.

Every event is timestamped at ingest with a non-qualified RFC 3161 timestamp from an independent public timestamp authority, which is cryptographically sound. Paid tiers add a daily qualified RFC 3161 checkpoint over the audit chain from an EU Trusted List QTSP; Enterprise adds per-event qualified timestamping.


7. Intellectual property

All intellectual property rights in the Attestsys apps, backend service, documentation, and website remain with Attestsys. These Terms do not transfer any intellectual property rights to you.

You grant us a limited, non-exclusive licence to process your data for the sole purpose of providing the service.


8. Service availability and SLA

The Attestsys service is provided on a "commercially reasonable efforts" basis for free-tier customers, with no uptime guarantee. Current operational state and incident history are published at status.attestsys.com.

For paid tiers, service level commitments (if any) are set out in the relevant Marketplace listing or Enterprise contract.

We are not responsible for any unavailability caused by:

  • Atlassian platform outages or maintenance (Atlassian's SLA applies)
  • Force majeure events
  • Scheduled maintenance windows (notified in advance)

9. Security vulnerability disclosure

If you discover a security vulnerability in an Attestsys app or service, please report it responsibly to security@attestsys.com.

We commit to responding to reported vulnerabilities in accordance with the Atlassian Security Bug Fix Policy for Marketplace apps:

SeverityResponse commitment
Critical10 days
High4 weeks
Medium12 weeks
Low25 weeks

10. Limitation of liability

To the maximum extent permitted by applicable law:

  • No consequential loss: Attestsys shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from your use of the Attestsys service, even if advised of the possibility of such damages.
  • Liability cap: Our total aggregate liability to you in connection with these Terms shall not exceed the greater of (a) the total fees paid by you for the Attestsys service in the 12 months preceding the claim, or (b) €100 (one hundred euros) for free-tier customers.
  • Carve-outs: Nothing in these Terms limits liability for death or personal injury caused by negligence, fraud, or any other liability that cannot be limited by law.

11. Warranties and disclaimers

The Attestsys service is provided "as is" and "as available". We disclaim all warranties, express or implied, including but not limited to implied warranties of merchantability, fitness for a particular purpose, and non-infringement.

We do not warrant that the service will be error-free, uninterrupted, or free from security vulnerabilities.


12. Termination

12.1 Termination by you

You may terminate your use of the Attestsys apps at any time by uninstalling them from your Jira workspace through the Atlassian Marketplace.

12.2 Termination by us

We may suspend or terminate your access to the service immediately upon notice if:

  • You breach these Terms materially and (if the breach is remediable) fail to remedy it within 14 days of notice
  • You fail to pay applicable fees (for paid tiers)
  • We are required to do so by law or by Atlassian

12.3 Effect of termination

Upon termination, we will retain your data for 60 days to allow you to export evidence bundles, then delete it, unless a longer retention period is required by law or agreed in an Enterprise contract. Backups may persist for up to 30 additional days before backup rotation deletes them. The cryptographic audit chain data is preserved (with redaction markers as appropriate) until the retention period expires.


13. Changes to these Terms

We will provide at least 30 days' notice of material changes to these Terms, by posting an updated version on this page and (where reasonably practicable) by notification through the Atlassian Marketplace. Continued use of the service after the effective date of changes constitutes acceptance.


14. Governing law and jurisdiction

These Terms incorporate the governing-law structure of our Additional Terms (the Provider-Specific Terms supplement to the Bonterms Standard End User Agreement):

  • If you are in the UK or EU: these Terms are governed by the laws of the Federal Republic of Germany, excluding the conflict-of-laws rules and excluding the UN Convention on Contracts for the International Sale of Goods (CISG). Disputes shall be subject to the exclusive jurisdiction of the courts of Ulm, Germany.
  • Everywhere else: California law applies per the default in the Bonterms Standard End User Agreement.

Mandatory consumer-protection law in your jurisdiction applies notwithstanding the above.


15. Contact

For legal enquiries relating to these Terms:

Email: legal@attestsys.com Postal: Ilgiz Khusnullin, Berblingerstr. 3, 89073 Ulm, Germany