Because the app is not eligible for it, and saying so seemed better than implying a badge it cannot hold.
Runs on Atlassian requires an app to make no egress of in-scope end-user data at all. Warranty lookup is egress: a serial number goes to a manufacturer, and where a device is assigned to a person that serial can be personal data. The app could declare otherwise in its manifest and would then qualify. It does not, because the claim would be the wrong way round — the conservative reading is the honest one, and the badge is not worth the argument.
Everything the badge is meant to signal is still true and is checkable above: Forge-hosted compute and storage, no external service of ours, no analytics, and an egress allowlist of exactly three manufacturer hosts.
Verification status, stated plainly
WarrantySync is a Forge app built for distribution through the Atlassian Marketplace, and will be subject to Atlassian’s app review before it is listed. It does not hold a SOC 2 or ISO 27001 certification of its own, and we do not imply one. Section 9 of the Cloud Security Statement sets out what that means in practice, including which of Atlassian’s certifications the underlying platform carries and which are therefore not ours to claim.