← Back to PointPoker

Security Policy

Last updated: April 15, 2026

Overview

PointPoker is built with a security-first architecture. This document describes how we protect your data across all platforms: the web application, Jira integration, Slack bot, and Microsoft Teams app.

Encryption

In transit

At rest

Authentication

PointPoker uses multi-layer authentication that varies by platform:

Web application

Jira integration

Slack and Microsoft Teams

Access controls

Tenant isolation

For platform integrations (Jira, Slack, Teams), all data is scoped by tenant identifier (Atlassian cloudId, Slack workspace ID, Teams tenant ID). Data from one organization cannot be accessed by another. Storage keys include the tenant identifier as a prefix, ensuring strict isolation.

Input validation

Data minimization

Infrastructure

Vulnerability management

Incident response

In the event of a security incident, we will:

Responsible disclosure

If you discover a security vulnerability in PointPoker, please report it to support@pointpoker.co. We will acknowledge receipt within 48 hours and work to resolve confirmed vulnerabilities promptly.

Contact

Questions about our security practices? Contact us at support@pointpoker.co.