Charts, dashboards and timesheets built on your Jira data — computed and stored entirely on Atlassian infrastructure. Nothing routed through a vendor's servers, nothing to argue about in a security review.
Real working software on sample data. The same interfaces render inside Jira — the only difference is where the numbers come from.
620 generated issues so you can explore without connecting anything. Installed in Jira it reads your real projects, and every query is constrained to what the person looking at it is allowed to see.
Type into any cell — 2h, 1.5, 90m and 1h30 all parse. Start the timer, mark work billable, then submit the week for approval.
Built to match what the established apps do, without the parts most teams never touch.
Most reporting and timesheet apps copy your Jira data onto the vendor's servers to make queries fast. Bastion Helix runs on Atlassian Forge, so compute and storage both stay inside Atlassian's boundary. There is no vendor database holding your issues or your hours, because there is no vendor server.
A timesheet says who worked, for how long, on whose account. That is personal data with a works council, a data protection officer and a retention policy attached to it. Keeping it inside Atlassian's boundary turns a procurement conversation into a non-event.
Aggregates are built with app-level access, but every query is constrained to what the viewer may see. Projects using an issue security scheme are answered by a live query run as that user, so Jira itself decides.
Atlassian licenses every app separately at your full user tier, so three apps means three bills. A suite collapses that into one. Prices at the 100-user tier.
Comparison prices are Atlassian Marketplace list prices at 100 users, checked August 2026. Modules ship over time; each is included for existing customers at no extra cost. Free for teams of 10 or fewer, as Atlassian requires.
Install straight into Jira Cloud. Billed on your existing Atlassian invoice, no new vendor to onboard, no purchase order. Free 30-day trial.
A standalone version connecting over the API, for teams whose work lives outside Jira or across several trackers. Join the list to hear when it opens.
Shared data layer, shared permissions model, shared settings. Each module after the first costs a fraction of the one before it — which is why the whole suite fits under one price.
No. Both modules are in active development and the Marketplace listing isn't live. The demos above are real working software running on generated data, so you can judge the products before committing anything. Join the list and you'll hear the day early access opens.
The app runs on Atlassian Forge. Code executes on Atlassian's compute and data is written to storage inside Atlassian's boundary. There is no Bastion Helix server in the path — we could not read your issues or your hours if we wanted to. That's what Atlassian's Runs on Atlassian designation certifies, and we're building to qualify from the first release.
That's the plan, and it's the feature that makes switching possible at all. Tempo exposes worklogs, accounts and attributes over an API, and a one-time import maps them across preserving dates, authors, descriptions and billable flags. Without it nobody can leave, so it's near the front of the queue rather than the back.
Jira's API is too slow to draw charts from directly, so the app keeps a pre-aggregated copy of your issues in Forge storage, refreshed incrementally. Worklogs sync more often than issues because they change more often. Reports query that copy rather than Jira. Every serious app in this space does the same — the difference is where the copy lives.
No. Every query is restricted to the projects the viewer can browse, with a separate rule for who may see whose hours. Projects using an issue security scheme are excluded from the aggregate path and answered by a live query run as that user.
You shouldn't, on faith. What you can check: the app requests read-only Jira scopes, stores nothing outside Atlassian, and can be uninstalled in one click taking its data with it. The architecture is the argument, not the logo.
An independent developer, working in the open. Small enough that support goes straight to the person who wrote the code, which is the one advantage a new vendor genuinely has over a large one.
One email when early access opens. Nothing else — no newsletter, no drip sequence, and the list isn't shared with anyone.
Early access members get the first year at launch pricing, locked.