Security Policy

Last Updated: 6 August 2026 · Last Verified: 6 August 2026

1. Overview

Compliance Glossary for Confluence is built on Atlassian Forge, Atlassian's cloud app development platform. The App runs entirely within Atlassian's infrastructure. We do not operate external servers, databases, or cloud services for this App. All data processing and storage happens within the Forge platform.

2. Infrastructure Security

The App's infrastructure security is provided by the Atlassian Forge platform:

Atlassian maintains SOC 2, ISO 27001, and other certifications for their cloud infrastructure. Details are available in Atlassian's Trust Center.

3. Authentication & Access Control

The App uses Forge's built-in authentication mechanisms exclusively:

4. Data Protection

Release-gated AI-assisted curation: this capability is not enabled in the current Marketplace release. It uses Forge LLM capability only after the required Marketplace major-version upgrade and administrator approval. Before release, DailyMind will verify and publish the applicable data flow, processor/retention terms, and Marketplace/privacy disclosures. We do not make a “no data egress” claim for that capability before those conditions are complete.

5. Code Security

6. Vulnerability Reporting

We take security vulnerabilities seriously. If you discover a security issue in Compliance Glossary for Confluence, please report it responsibly:

Please do not publicly disclose the vulnerability until we have had a reasonable opportunity to address it. We will not take legal action against researchers who report vulnerabilities in good faith.

7. Incident Response

In the event of a security incident affecting the App:

For incidents related to the underlying Atlassian Forge platform or infrastructure, Atlassian's own incident response process applies. See Atlassian's Security Incident Management.

8. Compliance

For full details on data handling, see our Privacy Policy.

9. Insurance

Professional Indemnity and Cyber Liability cover is on a milestone-based procurement plan with a Cyprus broker. Binding triggers, whichever occurs first: (a) a paid customer commits to 6 months of service, or (b) 3 paying customers in total. Target cover ~€3,000/yr. Until a trigger fires, the company carries no PI/Cyber policy — this is disclosed up front so procurement teams can decide whether the milestone gate works for their risk threshold. Once bound, the certificate of insurance will be available on request.

10. Contact

For security-related inquiries: security@teamkit.dev

For general questions: compliance-glossary@teamkit.dev

DailyMind LTD
Limassol, Cyprus

Compliance for Confluence

See how Compliance for Confluence turns approved terminology into audit evidence inside Confluence.