RuleMesh for Jira
Transform GDPR regulations into prioritised engineering tasks inside Jira, mapped to AWS, Azure, and security controls (OWASP TOP 10, NIST-CSF). Engineers use AI coding agents to implement compliance requirements directly from bundle tickets.
Three roles, one workflow
Engineers
- checkBundle tickets with implementation guidance
- checkMCP commands for AI-assisted compliance
- checkEvidence auto-tracking from coding agents
DPOs / Compliance Officers
- checkInteractive checklists with audit trails
- checkEvidence verification workflow
- checkFull regulatory traceability per item
Jira Admins
- checkOne-click site setup — no separate account needed
- checkLicense management from within Jira
- checkBacklog configuration and regeneration
Features
Site Registration
One-time setup connecting your Jira site to RuleMesh. No separate RuleMesh account required — the app auto-creates an organisation and FREE license for your site.
Open RuleMesh in Jira
A Jira administrator opens the RuleMesh project page. The app detects the site is not yet registered.
Connect to RuleMesh
Admin clicks "Connect to RuleMesh". The app registers the Jira site using the Forge-provided identity. An organisation and FREE license are auto-created.
Site key stored
A site key and webhook secret are stored securely in Forge Storage. All subsequent API calls use the site key.
Generate your backlog
Configure your environment (cloud provider, app type, data sensitivity) and generate a full GDPR compliance backlog in your Jira project.
Non-admin users see a message directing them to contact a Jira administrator. Admin turnover: if the original admin leaves, a new admin can take over via the transfer-admin flow — all data is preserved.
MCP Integration
How evidence flows
Supported Agents
| Agent | Config Location |
|---|---|
| Claude Code | .claude/settings.json or claude_desktop_config.json |
| Cursor / VS Code | .cursor/mcp.json or VS Code MCP settings |
| Windsurf | Agent MCP configuration |
See the MCP Server documentation for full setup instructions and configuration options.
Compliance Checklist
Every bundle ticket gets an interactive checklist in the Jira sidebar. The panel header shows a live progress lozenge (e.g., “4/7 answered”).
Status Tracking
Set each item to Yes, No, or N/A with a single click
Comments
Add implementation notes or justifications per item
Evidence Upload
Attach files directly to checklist items via Jira Attachments API
Verification
A second person marks items as verified — human-only, no MCP agents
Audit Trail
Expandable chronological log showing who changed what and when
Learn More
Modal showing the full regulatory chain: checklist item → IT requirement → source legal text
Technical Details
- infoChecklist data is stored as Jira entity properties on each issue, with adaptive chunking for large bundles (32KB entity property limit).
- infoOld tickets (pre-v7.0) get their checklist initialised on first panel open — no migration needed.
Dashboard
Bundles
Done
Active
To Do
High Risk
Verified
Dashboard Tabs
The dashboard organises compliance data across five focused views.
| Tab | Content |
|---|---|
| Overview | Metric cards + bundle list with progress bars, risk badges, and status |
| Risk Matrix | Stacked bar visualisation of risk levels across all bundles |
| Reports | Evidence timeline with date, bundle, and signal type filters |
| Intelligence | Regulatory intelligence feed with severity filtering (INTEL tier) |
| MCP | MCP setup instructions, API key display, agent connection guide |
License Tiers
| Feature | FREE | FREE + INTEL |
|---|---|---|
| Price | $0 | +$299/year |
| GDPR requirements / month | 100 | Unlimited |
| Projects | 1 | 5 |
| Compliance Checklist | check_circle | check_circle |
| MCP Integration | check_circle | check_circle |
| Evidence Tracking | check_circle | check_circle |
| Regulatory Intelligence | remove | check_circle |
| Version Tracking | remove | check_circle |
Upgrade from within Jira. Clicking “Upgrade” generates a secure one-time token (15-minute TTL) and redirects to the RuleMesh pricing page. The license updates automatically after payment.
Data & Security
Data Storage
Bundles, backlog state, site keys, licenses
Checklist data per ticket (32KB, chunked)
Evidence files
Compliance data, evidence signals, license
Security
- shieldSite authentication via X-Site-Key header
- shieldWebhook authentication via HMAC-SHA256 signing
- shieldAll data encrypted at rest (AWS RDS, DynamoDB)
- shieldData hosted in EU (Frankfurt)
- shieldData retention: 30 days post-uninstall, then deleted
Install RuleMesh for Jira and generate your GDPR compliance backlog in minutes.