SECURITY
Security policy
How AccessLens for Confluence is designed, operated and supported to protect customer data.
Scope
This policy describes the security architecture and operational safeguards for AccessLens for Confluence, a Forge-hosted application published by TechnofyStore. It applies to the application code, Forge-hosted processing and Forge SQL data used to deliver the service.
Architecture and data boundary
AccessLens is a read-only Confluence Cloud application. Application compute runs on Atlassian Forge and operational data is stored in Forge SQL, isolated by app installation. The app does not use Forge Remote, a partner-hosted backend, external storage, advertising, analytics, session replay or partner-selected third-party data processors.
Confluence page bodies are retrieved only to perform the requested analysis and are processed in memory. AccessLens retains the minimum operational metadata needed to track findings: page and space identifiers, titles, versions, timestamps, owner account identifiers where available, finding fingerprints, limited evidence, remediation guidance, scan settings, exceptions and audit events. It does not intentionally retain full page bodies, attachments, credentials, payment data or API tokens.
Authentication, authorization and least privilege
Installation, user authentication and product access are governed by Atlassian Cloud and Atlassian Marketplace. AccessLens does not collect Atlassian passwords, personal access tokens, API tokens or third-party credentials.
The app uses Forge asApp() access with only read:page:confluence, read:space:confluence and report:personal-data. These permissions allow the app to list selected spaces, read pages for accessibility analysis and meet Atlassian personal-data reporting obligations. AccessLens has no Confluence write, delete, administration, email-address or permission-management scope.
Data egress and network exposure
AccessLens does not transmit customer data to remote hostnames or IP addresses outside Atlassian. Confluence API calls are made through Forge to the customer’s Atlassian Cloud site. The app declares no Forge Remote backend, external fetch permissions or public web triggers, and exposes no partner-hosted API endpoint.
Platform and application safeguards
- Atlassian-managed Forge runtime, service authentication, storage isolation and platform encryption controls.
- Tenant-scoped repository operations and installation-scoped Forge SQL storage.
- Server-side allowlists and validation for resolver input types, identifiers, UUIDs, lengths and dates.
- Prepared SQL statements with bound parameters; user input is not interpolated into SQL.
- React’s default HTML escaping for customer-controlled rendered values.
- Content Security Policy and restrictive browser security headers on the public policy site.
- No intentional logging of credentials, access tokens, full page bodies or unnecessary personal data.
- Dependency review, automated tests and production validation before releases.
Personal data and deletion
Where Atlassian account identifiers are retained for page ownership or operational audit purposes, AccessLens uses Forge Personal Data Reporting. Account identifiers are removed from applicable stored fields when Atlassian’s privacy workflow indicates that the account is closed. See the Privacy Policy for data categories, purposes and retention.
Vulnerability management
TechnofyStore assesses reported vulnerabilities according to exploitability and potential impact, prioritises remediation of material security issues and updates dependencies when compatible security releases are available. Security fixes are tested and deployed through the Forge release process.
Customers and researchers should report suspected vulnerabilities privately through the TechnofyStore support portal. Reports should include the affected app version, Atlassian site URL, approximate timestamp, impact and minimal reproduction steps. Do not include credentials, access tokens, full page bodies or unnecessary personal data.
Security incident response
TechnofyStore investigates suspected security incidents, limits further exposure where applicable, preserves relevant diagnostic information and coordinates with Atlassian when the Forge platform or Atlassian-hosted data may be affected. Material incidents are communicated to affected customers and Atlassian in accordance with applicable contractual and legal obligations.
Report a security issue
Submit a private security request through the TechnofyStore support portal. Security reports are handled privately and should not be posted in public Marketplace reviews or community forums.
Policy updates
This policy may be updated as the application, Forge platform or applicable security requirements evolve. The effective date above identifies the latest published version.