Security Policy
Last Updated: 6 August 2026 · Last Verified: 6 August 2026
1. Overview
Compliance Glossary for Confluence is built on Atlassian Forge, Atlassian's cloud app development platform. The App runs entirely within Atlassian's infrastructure. We do not operate external servers, databases, or cloud services for this App. All data processing and storage happens within the Forge platform.
2. Infrastructure Security
The App's infrastructure security is provided by the Atlassian Forge platform:
- Sandboxed execution — App code runs in Atlassian's Forge sandbox (Node.js runtime declared in our manifest), isolated from other apps and customer environments. The sandbox restricts network access, file system access, and available APIs.
- Data encryption at rest — All data in the Forge Entity Store is encrypted at rest by Atlassian. Encryption key management is handled by Atlassian's infrastructure.
- Data encryption in transit — All communication between the App and the Atlassian platform uses TLS encryption.
- Data isolation — Each Atlassian installation has its own isolated data partition in the Forge Entity Store. No installation can access another's data.
- No external infrastructure — We do not run servers, databases, or any external services that the App connects to. There is no external attack surface for the App itself.
Atlassian maintains SOC 2, ISO 27001, and other certifications for their cloud infrastructure. Details are available in Atlassian's Trust Center.
3. Authentication & Access Control
The App uses Forge's built-in authentication mechanisms exclusively:
- Forge auth — The App authenticates using
api.asApp()andapi.asUser()provided by the Forge platform. No personal access tokens, passwords, API keys, or shared secrets are used or stored. - Role-based access — The App enforces role-based access control. Administrative actions (managing glossary terms, configuring settings, managing access control lists) are restricted to users with appropriate Confluence permissions or app-level admin roles.
- Four-eyes approval workflow — Glossary terms go through a review and approval workflow. A term cannot be approved by the same person who submitted it for review, enforcing separation of duties as required by regulatory frameworks.
- No credential storage — The App does not store any user credentials. Authentication is fully delegated to the Atlassian platform.
4. Data Protection
- Storage — All data is stored exclusively in Atlassian's Forge Custom Entity Storage (KVS / Entity Store). No data is stored outside the Atlassian platform.
- No external transmission in the current Marketplace release — The current App does not make external API calls or send data to third-party services. Its manifest contains no
external:fetch:backendpermission. - Read-only Confluence access — The App reads Confluence page content solely for compliance scanning purposes. It does not modify, delete, or create Confluence pages. Page content is processed in-memory and not stored — only scan findings are persisted.
- Minimal personal data — The App stores only Atlassian account IDs as part of the audit trail. No names, email addresses, or other profile information is stored by the App. Account IDs are used to maintain the regulatory audit trail required by frameworks such as 21 CFR Part 11 and ISO 13485.
- Export security — Exported CSV files are generated by the App's Forge resolver (running inside Atlassian's Forge runtime) and returned to the user's browser. Generation and delivery happen entirely within Atlassian's infrastructure — no external server is involved.
Release-gated AI-assisted curation: this capability is not enabled in the current Marketplace release. It uses Forge LLM capability only after the required Marketplace major-version upgrade and administrator approval. Before release, DailyMind will verify and publish the applicable data flow, processor/retention terms, and Marketplace/privacy disclosures. We do not make a “no data egress” claim for that capability before those conditions are complete.
5. Code Security
- Forge security review — All Forge apps undergo Atlassian's security review process before being listed on the Atlassian Marketplace. This includes static analysis and review of requested permissions and scopes.
- Permission-scoped execution — The Forge runtime restricts the App's capabilities to declared permissions only. The App cannot access the file system, spawn processes, or make arbitrary network connections.
- No external dependencies for data processing — The App does not rely on external libraries or services for processing customer data. All compliance scanning logic runs within the App's own codebase inside the Forge sandbox.
- Source control — Source code is managed in private repositories with access restricted to the development team.
6. Vulnerability Reporting
We take security vulnerabilities seriously. If you discover a security issue in Compliance Glossary for Confluence, please report it responsibly:
- Email: security@teamkit.dev
- What to include: a description of the vulnerability, steps to reproduce, and the potential impact
- What to expect: we aim to acknowledge within 3 business days and provide an initial assessment within 10 business days
Please do not publicly disclose the vulnerability until we have had a reasonable opportunity to address it. We will not take legal action against researchers who report vulnerabilities in good faith.
7. Incident Response
In the event of a security incident affecting the App:
- We will investigate the scope and impact of the incident promptly
- Affected customers will be notified through their Atlassian site administrator contact and via the Atlassian Marketplace listing
- We will provide a clear description of what happened, what data was affected, and what remediation steps are being taken
- A post-incident summary will be made available once the issue is resolved
For incidents related to the underlying Atlassian Forge platform or infrastructure, Atlassian's own incident response process applies. See Atlassian's Security Incident Management.
8. Compliance
- GDPR — DailyMind LTD acts as a data processor for personal data stored through the App. The App stores only Atlassian account IDs as part of the audit trail. No special categories of personal data are processed. For data we process on our own behalf (e.g., support correspondence, website analytics), we act as controller. See our Privacy Policy and DPA for the full allocation of roles.
- Personal data reporting — The App implements Atlassian's Personal Data Reporting API, reporting all stored account IDs to the Atlassian platform on a weekly cycle.
- Right to erasure — When Atlassian signals that a user account has been closed, the App automatically anonymizes all references to that account ID across glossary terms, version history, finding resolutions, and access control lists.
- Data deletion on uninstall — When the App is uninstalled, all per-installation data in the Forge hosted storage is soft-deleted by Atlassian and then permanently deleted in line with Atlassian's Standard Data Retention and Disposal policy (documented in Atlassian's SOC 2 report). See Atlassian's Data lifecycle for Forge-hosted storage.
- No cookies or client-side tracking — The App itself does not use cookies, local storage, or any client-side tracking mechanisms.
For full details on data handling, see our Privacy Policy.
9. Insurance
Professional Indemnity and Cyber Liability cover is on a milestone-based procurement plan with a Cyprus broker. Binding triggers, whichever occurs first: (a) a paid customer commits to 6 months of service, or (b) 3 paying customers in total. Target cover ~€3,000/yr. Until a trigger fires, the company carries no PI/Cyber policy — this is disclosed up front so procurement teams can decide whether the milestone gate works for their risk threshold. Once bound, the certificate of insurance will be available on request.
10. Contact
For security-related inquiries: security@teamkit.dev
For general questions: compliance-glossary@teamkit.dev
DailyMind LTD
Limassol, Cyprus
Compliance for Confluence
See how Compliance for Confluence turns approved terminology into audit evidence inside Confluence.