App rejected twice with "Security requirements not met" — cannot access ECOHELP review tickets to see the reason

My Forge app BastionTrail: Self-Hosted Git & Audit Trail for Jira (app ID 2261345884) was rejected twice during approval, both times with only the generic reason “Security requirements not met” — review tickets ECOHELP-147215 and ECOHELP-147515.

I am the submitter (wferreira.civil@gmail.com) but I get “you don’t have permission to view this request” on both tickets, so I cannot read the reviewer’s comments. The password-reset link in the submission email returns a 404 (it points to username hub@atlassian.com). I opened ECOHELP-147229 asking for access and the reason, but there is no reply yet.

Between the two rejections I already:

  • removed an unused write:jira-work scope (the app is now read-only on Jira);
    • removed all unauthenticated read endpoints from my backend, so linked development data is served only through the Forge-authenticated (FIT) channel;
      • confirmed the egress endpoint has a valid TLS certificate.
    • None of that cleared the rejection, so the actual blocking issue is something I still cannot see. Could an Atlassian staff member please grant my account access to ECOHELP-147215 and ECOHELP-147515, or share the specific security reasons and the required changes. I am ready to fix and resubmit. Thank you.

Hi @williamferreira , the awesome support folks helped us fix your access. Can you try it now? You should have access already.

Cheers,

Ian