Open source projects can apply to use JIRA Cloud for free, but there's no further information or contact info aside from a sign-up form — https://www.atlassian.com/software/views/open-source-license-request — so I'm asking here:
Is it possible for open source JIRA Cloud admins to set up restricted projects, e.g. a "security" project, which only certain users can see, where members of the public can responsibly disclose security issues?
I would guess that open source JIRA Cloud admins wouldn't be any more restricted than regular JIRA Cloud users, but it would be nice to be sure before going through the sign-up process (though the lack of LDAP support may well be a killer anyway).