Skip to main content

What data privacy protections apply when using Vansah’s AI features?

Updated this week

1. Types of Data Processed

AI features in Vansah can process:

  • Requirements / User Stories: Extracted from Jira Work Items or Confluence pages if selected.

  • Work Item Details: Summaries, descriptions, linked issues.

This often involves business-sensitive information, since it reflects project requirements, failures, and operational risks.


2. Data Residency and Storage

  • Vansah uses data residency support across multiple regions (e.g., AU, US, EU, Asia)


3. Anonymization and Minimization

  • Only the requirement description and relevant metadata is processed and not the entire project space.

  • Sensitive fields are anonymized before being sent for AI processing. It is generally considered best practice to avoid storing highly sensitive data directly within Jira due to inherent security considerations. While Jira offers various security features and add-ons to enhance data protection, it recommends against storing confidential information like passwords, financial records, or sensitive personal data.


4. Third-Party AI Providers

  • Vansah uses external AI APIs (OpenAI), the data may leave Vansah’s infrastructure during processing.

  • OpenAI is configured to not store prompts at all and it has been restricted from using data to train its models.


5. Compliance and Security Frameworks

  • Vansah aligns with ISO 27001, GDPR, and SOC 2. Certification is currently in progress and expected to be available by October 2025.

  • This means AI features must follow:

    • Purpose limitation (only process what’s needed for the feature).

    • Access controls (AI does not override user roles/permissions).

    • Auditability (customers are made aware of what data is processed and when)

    • Opt in/out (Customers with the right Jira privileges need to opt-in to utilize Vansah's AI features


6. Customer Responsibilities

  • Avoid embedding sensitive PII (e.g., patient records, financial identifiers) inside test cases if AI will process them.

  • Use labels, placeholders, or synthetic test data when possible.

  • Review Vansah’s AI privacy and residency settings to ensure compliance with internal policies.

Did this answer your question?