Nexus · test management for Jira
Menu
Get started
Nexus overview ↗Trust and control

Your work. Your control.

Built on Atlassian Forge, with Jira permissions and a clear boundary for the AI provider you choose.

Get started →
  1. Jira identity
  2. Access controls
  3. Data handling
  4. Human review
  5. Audit history


01 / Your data, in context

Understand where your information lives.

Nexus runs on Atlassian Forge. Your testing records live in Jira and Forge storage, without a separate Resync application server holding a copy of your project.

ATLASSIAN PLATFORM

Your Jira site + Nexus

JIRA RECORDS

The work your team owns

Test cases, test sets and test executions are Jira issues. Test steps and design details are stored on issue properties, alongside the links connecting your evidence.

FORGE STORAGE

The context behind the work

Nexus stores run results, test-data sets, environment records, settings, review drafts and audit history in app storage associated with your site.

External AI is a separate processing boundary.

When you use Nexus Pro AI, the content needed for that action goes to the provider your administrator connects. Its processing terms apply there.

See what is shared ↓

02 / Access & administration

Keep control with your administrators.

Jira permissions and Nexus settings determine who can work with your testing records and manage the app.

Jira identity and permissions

People use their Atlassian identity. Nexus checks Jira access for the work they view or change, including issue-level restrictions. Your Jira administrators remain responsible for project membership and permission schemes.

Separate site and project controls

Jira administrators manage Nexus Setup, the connected AI account and backup and restore. Project administrators manage project settings, roles, workflows and retention.

Credentials stay out of the browser

Your AI provider key is held in Forge secret storage and is not returned to the browser. CI API keys are shown once and stored as salted hashes. Keep credentials in your CI secret store and replace them when access changes.

Accountability without copied profiles

Audit records use Atlassian account IDs to record who acted. Names and avatars are resolved from Jira for display rather than stored as separate Nexus user profiles.

03 / AI on your terms

Know what leaves the platform.

Core test management works without external AI. Nexus Pro uses your organisation's own provider account when an AI action is run.

YOU CHOOSE THE CONNECTION

One provider. Your account. Your agreement.

A Jira administrator selects Anthropic, OpenAI, Google, Moonshot Kimi or xAI Grok and the model used by Nexus. The provider key stays in Forge; the request goes from Forge to that provider without passing through a Resync server.

The action determines the content sent: for example, requirement summaries, descriptions and acceptance criteria, or the test-case steps being worked on. Optional comments and selected attachments can add content, so review those choices before running the action.

Your agreement with the provider governs its processing, retention and region. Nexus does not offer region-pinned external AI processing.

Explore AI features and controls →

Rovo is an Atlassian service with its own availability and terms. Enabling Rovo is separate from connecting an external AI account in Nexus Pro.

04 / PII & sensitive test data

Use safe inputs.
Review what you share.

Prefer synthetic test data. Nexus provides dataset scanning, classification and masking controls to help teams manage sensitive values.

See how test data works →

Detect likely personal information

Dataset scanning flags patterns such as email addresses, payment-card numbers and New Zealand identifiers. Review scanner findings before publishing; detection does not guarantee that every sensitive value has been found.

Mask sensitive dataset values

Sensitive datasets display masked values by default. Owner and owner-group controls govern explicit reveals, and reveal activity is recorded. Choosing the masked classification does not anonymise values for you.

Restrict AI example rows

AI test-data suggestions can include up to five synthetic example rows only when you opt in. Masked and sensitive dataset rows are excluded from these examples.

Review requirements and test content too

Dataset controls do not replace a review of requirement text, test steps or attachments. Remove personal information, credentials and confidential content that your organisation has not approved for the connected provider before running an AI action.

05 / History & recovery

Keep evidence.
Plan for recovery.

Set retention to match your organisation's needs and keep a separate backup of Nexus app data.

RETENTION

Working history and audit evidence

Working history is retained for 180 days by default, with project settings from 30 to 3,650 days. Audit records default to seven years, adjustable from one to ten years. Findings awaiting review remain until reviewed.

Record types have different retention rules. Review the privacy policy before deciding what your team needs to keep.

BACKUP & RESTORE

Export your app data separately

Nexus Setup includes backup and restore for Jira administrators. Jira site backups do not include Nexus Forge app data, so keep both as part of your recovery process.

Nexus backup files exclude secrets such as AI provider keys and CI credentials. Store exports securely and configure credentials again after a restore.

LEAVING NEXUS

Your Jira issues stay in Jira

Uninstalling Nexus does not delete your Jira test cases, sets or executions. Forge app storage has a separate Atlassian retention lifecycle; export your Nexus data before uninstalling.

Read the backup and restore guide →

06 / Clear answers

Questions for your security review.

Use the privacy policy for the full data-handling description, or contact us about your organisation's review.

Read the privacy policy
What can Resync see?

Resync does not receive your project content through a separate application backend. We can see operational Forge logs and the installation and licensing information Atlassian shares with vendors. Anything you send to support, including screenshots, is also visible to the support team. Share only what is needed to investigate your question.

Does Resync use our data to train AI?

Resync does not use your data to train AI models. For a connected external AI provider, processing and data use are governed by your organisation's agreement with that provider. Check those terms before connecting an account.

What happens when we connect a migration tool?

Administrator-configured Pro migrations read test content from supported Xray, Zephyr Scale or AIO Tests accounts into Jira. The connection uses the credentials and source project you supply. Review the migration section of the privacy policy before connecting a source.

Where can we ask a security or privacy question?

Visit Nexus support for contact details. Describe the concern and affected workflow; avoid including provider keys, CI credentials or unnecessary personal data in your message.