1. Types of Data Processed
AI features in Vansah can process:
Requirements / User Stories: Extracted from Jira Work Items or Confluence pages if selected.
Work Item Details: Summaries, descriptions, linked issues.
This often involves business-sensitive information, since it reflects project requirements, failures, and operational risks.
2. Data Residency and Storage
Vansah uses data residency support across multiple regions (e.g., AU, US, EU, Asia)
3. Anonymization and Minimization
Only the requirement description and relevant metadata is processed and not the entire project space.
Sensitive fields are anonymized before being sent for AI processing. It is generally considered best practice to avoid storing highly sensitive data directly within Jira due to inherent security considerations. While Jira offers various security features and add-ons to enhance data protection, it recommends against storing confidential information like passwords, financial records, or sensitive personal data.
4. Third-Party AI Providers
Vansah uses external AI APIs (OpenAI), the data may leave Vansah’s infrastructure during processing.
OpenAI is configured to not store prompts at all and it has been restricted from using data to train its models.
5. Compliance and Security Frameworks
Vansah aligns with ISO 27001, GDPR, and SOC 2. Certification is currently in progress and expected to be available by October 2025.
This means AI features must follow:
Purpose limitation (only process what’s needed for the feature).
Access controls (AI does not override user roles/permissions).
Auditability (customers are made aware of what data is processed and when)
Opt in/out (Customers with the right Jira privileges need to opt-in to utilize Vansah's AI features
6. Customer Responsibilities
Avoid embedding sensitive PII (e.g., patient records, financial identifiers) inside test cases if AI will process them.
Use labels, placeholders, or synthetic test data when possible.
Review Vansah’s AI privacy and residency settings to ensure compliance with internal policies.