> they could also send it somewhere

Run JiraTui in a container / bubblewrap, and only allow it to connect to the Jira API host:port.

Wouldn’t that mean they could still exfiltrate it to another jira site they control?