RuleMesh
Atlassian Jira
Atlassian Forge App · Live on the Marketplace

GDPR work, tracked where engineering already lives.

RuleMesh for Jira delivers GDPR articles as module epics with one sub-task per IT requirement, mapped to AWS, Azure, GCP, NIST CSF, and OWASP. The compliance checklist on every module ticket auto-completes from your coding agent's evidence signals. No separate audit portal, no source-code uploads.

Install from Atlassian Marketplace
The App

What you are looking at, screen by screen

These are real screens from the app, with the numbers a live GDPR backlog produces. Read them here and the first session inside Jira will feel like a second visit.

01Dashboard Tab

Every module, and what is blocking release

The project page opens on an execution surface, not a scoreboard. Seven GDPR modules, live checklist counts pulled from the tickets themselves, and a recommended next module with the MCP command already written.

  • Evidence sync banner

    Shows the last reconciliation cycle and when the next one runs, so nobody has to guess whether the numbers are current.

  • Six metric cards

    Modules, Done, Active, To Do, High Risk and Verified, counted from the live tickets, not from a separate tracker.

  • Module list

    Each row links straight to its Jira issue and carries a risk badge, an answered/total checklist count and a verified count.

  • Recommended next module

    A ready-to-paste prompt naming the module and its ID, so an engineer can hand the work to a coding agent in one copy.

Dashboard Tab
02Compliance Checklist Panel

The checklist lives on the ticket, in the Jira sidebar

Engineers never leave the issue they are working. Every module ticket carries an interactive checklist: answer, note, attach, verify, with each item tagged with the article it comes from and its risk level.

  • Verification progress

    Three separate counts (answered, verified, and with evidence) because answered is not the same as proven.

  • Article + risk tags

    Each item shows the GDPR article it derives from and whether it is high or moderate risk.

  • Yes / No / N/A

    One click to answer. Notes and evidence uploads attach to the individual item, not the whole ticket.

  • Evidence line

    Signals written back by a coding agent appear inline: file name, what was implemented, and the scan session. File names only; RuleMesh never reads or uploads your source.

  • Verified checkbox + audit trail

    A second human marks the item verified. The expandable audit trail records who changed what and when. Agents cannot verify their own work.

Compliance Checklist Panel
03Risk Matrix Tab

Decide what engineering attacks next

A risk view that stays readable when everything is red. Module-level risk on the left, the underlying high/moderate/low requirement mix as a stacked bar, and progress next to it, so priority is judged against effort already spent.

  • Risk tiers at a glance

    High, moderate and low module counts, plus the total number of high-risk requirements detected across the backlog.

  • Risk mix bar

    Per module, the split of high / moderate / low requirements underneath it, since a module flagged high is rarely uniformly high.

  • Progress beside risk

    Checklist completion sits in the same row, so a high-risk module at 10% reads differently from one at 80%.

Risk Matrix Tab
04Reports Tab

Scan history that reads as change, not noise

Every agent scan is a session. The Reports tab shows what moved between sessions (newly detected signals, resolved ones, and what stayed put) with the evidence broken down by where it came from.

  • Signals and change

    Current signals in the latest session, distinct scans, modules touched, and how much changed since the prior scan.

  • Evidence types

    Signals split by source (code, manual, test, documentation) so reviewers can see what is machine-detected and what a person asserted.

  • Trend chart

    Signal volume against change pressure over successive scan sessions.

  • Scan timeline

    Per session: how many signals, how many new, how many resolved, how many unchanged.

Reports Tab
Built For Your Team

Three roles, one workflow

code

Engineers

  • checkModule tickets with implementation guidance
  • checkMCP commands for AI-assisted compliance
  • checkEvidence auto-tracking from coding agents
verified_user

DPOs / Compliance Officers

  • checkInteractive checklists with audit trails
  • checkEvidence verification workflow
  • checkFull regulatory traceability per item
admin_panel_settings

Jira Admins

  • checkOne-click site setup, no separate account needed
  • checkLicense management from within Jira
  • checkBacklog configuration and regeneration
Capabilities

Beyond the four screens

The workflows behind the views: how the backlog gets created, how agents plug in, and who administers it.

playlist_add

Compliance Backlog Generation

Generate a complete GDPR backlog in your Jira project with one click. Modules group related IT requirements by compliance theme.

  • arrow_rightConfigure cloud provider, application type and data sensitivity
  • arrow_rightCreates a regulation Epic with one module Task per compliance theme
  • arrow_rightRisk badges and framework control mappings (AWS, Azure, OWASP, NIST-CSF)
  • arrow_rightTwo-phase creation for large backlogs (30+ modules) to stay inside Jira API limits
smart_toy

MCP Integration

Connect Codex, Claude Code, Gemini CLI, Cursor, or another coding agent to work requirements straight from module tickets.

  • arrow_rightAPI key generated on first visit to the MCP tab
  • arrow_rightEvery module ticket carries a copyable MCP command with its module ID
  • arrow_rightAgents submit evidence signals; the app reconciles them every 5 minutes
  • arrow_rightA structured "Evidence Found" comment is posted on the Jira ticket
newspaper

Regulatory Intelligence

Regulatory updates relevant to your posture, with severity filtering and one-click linking to the tickets they affect.

  • arrow_rightIntelligence cards with severity badges (High / Medium / Low)
  • arrow_rightQuick-add links an item to affected module tickets as a structured comment
  • arrow_rightAffected tickets shown per intelligence item
  • arrow_rightINTEL tier; FREE tier sees an upgrade prompt
admin_panel_settings

Site Setup & Admin

One-time registration from inside Jira. No separate RuleMesh account, no credentials to copy between systems.

  • arrow_rightAuto-registers on a Jira admin’s first visit using Forge-provided identity
  • arrow_rightOrganisation and FREE license created automatically for the site
  • arrow_rightBacklog can be regenerated from the dashboard
  • arrow_rightAdmin turnover handled by a transfer-admin flow, all data preserved
Getting Started

From install to backlog

One-time setup connecting your Jira site to RuleMesh. No separate RuleMesh account required. The app auto-creates an organisation and FREE license for your site.

1

Open RuleMesh in Jira

A Jira administrator opens the RuleMesh project page. The app detects the site is not yet registered.

2

Connect to RuleMesh

Admin clicks "Connect to RuleMesh". The app registers the Jira site using the Forge-provided identity. An organisation and FREE license are auto-created.

3

Site key stored

A site key and webhook secret are stored securely in Forge Storage. All subsequent API calls use the site key.

4

Generate your backlog

Configure your environment (cloud provider, app type, data sensitivity) and generate a full GDPR backlog in your Jira project.

Non-admin users see a message directing them to contact a Jira administrator. Admin turnover: if the original admin leaves, a new admin can take over via the transfer-admin flow, and all data is preserved.

AI Coding Agents

How evidence reaches the checklist

How evidence flows

terminalEngineer runs an MCP command on a module ticket
smart_toyCoding agent implements the requirement and calls submit_signals
cloud_uploadEvidence is stored in the RuleMesh API
syncEvery 5 minutes, the Jira app reconciles evidence events
fact_checkMatching checklist items are auto-updated with evidence signals
commentA structured "Evidence Found" comment is posted on the Jira ticket

The agent reports where evidence was detected: file names, the change made, and the scan session. RuleMesh never reads or uploads your source files. Verification of any item stays with a human reviewer.

Supported Agents

AgentConfig Location
Codex~/.codex/config.toml
Claude Codeclaude mcp add --transport http
Gemini CLI~/.gemini/settings.json
Cursor / VS Code.cursor/mcp.json or VS Code MCP settings
Other coding agentsStreamable HTTP server settings

See the MCP Server documentation for full setup instructions and configuration options.

Plans

Plans

The Jira app is free. What it reads is licensed on RuleMesh, so the plan that matters is your RuleMesh plan, and the current terms live in one place.

See plans and pricingarrow_forward

Upgrading from inside Jira generates a secure one-time token (15-minute TTL) and redirects you to RuleMesh to complete it.

Infrastructure

Data & Security

Data Storage

database
Forge Storage

Modules, backlog state, site keys, licenses

database
Jira Entity Properties

Checklist data per ticket (32KB, chunked)

database
Jira Attachments

Evidence files

database
RuleMesh API

Compliance data, evidence signals, license

Security

  • shieldSite authentication via X-Site-Key header
  • shieldWebhook authentication via HMAC-SHA256 signing
  • shieldAll data encrypted at rest (AWS RDS, DynamoDB)
  • shieldData hosted in EU (Frankfurt)
  • shieldData retention: 30 days post-uninstall, then deleted
view_kanbanJira Marketplace Live

Install the Jira app

Jira install is live. Open the Marketplace listing to connect RuleMesh to your engineering workflow and move verified evidence into Jira.

Marketplace installJira workflow enabledMCP evidence sync

Launch State

Jira is now in live install mode. Use the Marketplace listing to complete setup.

Install Jira App