Roles and contact
The customer determines why and how its tenant registry data is used, and Ing. Martin Pristaš, trading as Qentra Technologies, processes that data to provide the service. Qentra independently determines the purposes of entitlement, support, fraud-prevention, security and legal records. Exact roles depend on use, law and the applicable agreement. Contact support@qentra.tech.
What the registry stores
The remote stores a random Forge installation identifier, configured Jira project key, license and activity state; stable agent/external IDs; purpose and responsible function; provider/model version; environment, autonomy, lifecycle and risk tier; data-class and declared-tool metadata; evidence status, source class, measurement and expiry timestamps, sample counts and artifact digest; assessment result; and Jira remediation issue ID or key.
What it deliberately excludes
The service does not intentionally store prompts, conversations, model inputs or outputs, tool arguments or results, credentials, Jira issue bodies, comments or attachments, raw evidence artifacts, or a natural-person owner field. Forge principal information is reduced in memory to whether user context exists. Request headers and bodies are redacted and request logging is disabled.
Purpose and sharing
Data supports inventory, evidence assessment, license enforcement, security, requested remediation and aggregated product operations. It is not sold, used for behavioral advertising or used for cross-customer model training. Microsoft hosts the Qentra remote and Atlassian supplies Jira Cloud, signed Forge invocation and Marketplace licensing or billing.
Location, retention and deletion
The single-region remote runs in Microsoft Azure Poland Central on a shared Qentra-managed virtual machine with a separate private PostgreSQL service. The app does not offer customer-selected residency, Forge PINNED status or realm migration. Primary tenant records remain until customer deletion or uninstall; uninstall triggers tenant deletion and database cascades. Protected backup copies expire under the published recovery policy and are not used for ordinary processing. Durable restore/deletion replay remains a release gate.
Security and current release status
Traffic uses HTTPS, Forge calls require verified signed invocation tokens, administrative actions require a live Jira project-admin check, replay identifiers are bounded by token expiry, and application secrets are held in Azure Key Vault. The current build is a controlled pilot and is not represented as certified, independently pentested, highly available or generally available. See documentation, security, DPA status and support.