The catalogue
Apps
Access review, permission reporting, and compliance tooling for Jira Cloud — all of it built as pure Atlassian Forge apps. That is a deliberate constraint: it means the app runs on Atlassian’s infrastructure, stores what it needs inside your own tenant, and never sends your data to us.
What they share
Four things true of every app on this page
We build a narrow kind of software, and the constraints are the same every time. If you have reviewed one QuinTek app, most of the second review is already done.
They run where your data already lives
A Forge app executes on Atlassian’s compute and stores what it needs in Atlassian’s storage, scoped to your installation. Nothing is copied out to a vendor cloud to be processed, which is what makes the data-flow section of a security questionnaire short.
They read; they do not write
Our apps hold no scope that would let them change a permission scheme, a project role, a group, or an account. That halves the size of the review: the question is only what the app can see, never what it could break.
They tell you what they could not check
If a scan cannot read something, it says so and names it. A compliance tool that quietly reports on 90% of your estate as though it were all of it is worse than no tool, because the output still looks authoritative.
They install like any other Marketplace app
Bought through Atlassian, billed with the rest of your apps, covered by Atlassian’s 30-day trial. No separate account with us, no key to paste, no contract to sign before you can see whether it works.
What we build next
We build the report you are currently assembling by hand.
Every app here started the same way: an Atlassian admin describing a question their site could not answer, and the quarterly spreadsheet they built to answer it anyway. Access reviews, permission derivation, offboarding evidence, app-principal privilege — all of it lives in exports and pivot tables at most organisations, and none of it should.
Two things are already on the list because they are the ones people ask about most: Confluence space permissions, and issue security schemes. Both are real work rather than a checkbox — a different permission model in the first case, a second layer of restriction in the second — which is why neither was rushed into a first release. What we pick up next depends largely on what we get asked for.
Doing a review in a spreadsheet?
Most of what we build starts as somebody describing the quarterly export they dread. If that is you, tell us about it — we read every message.