Policy
1. Data Security
All data managed through Secure Vault for Confluence is securely handled within the Atlassian ecosystem.
No data is stored, transmitted, or processed outside of Confluence or Atlassian infrastructure.
The app does not send data to any external servers.
The app does not collect or process personally identifiable information (PII) unless explicitly entered by the user.
All data remains within the boundaries of Atlassian’s secure cloud environment.
Data handling strictly follows Atlassian’s security, privacy, and hosting standards.
2. Application Scope & Secret Handling
Secure Vault for Confluence enables controlled access to sensitive or restricted information within Confluence pages.
To maintain security and integrity:
Secret data is stored as part of Confluence macro configuration.
The app does not encrypt or transform data externally; it relies on Atlassian platform security.
Content is displayed only to authorized users or groups defined in the configuration.
The app does not execute scripts, HTML, or embedded code.
All content is treated strictly as static data and rendered safely.
Any malformed or unsupported configuration may result in display limitations.
3. Authentication & Permissions
The app operates strictly within Atlassian’s authentication and permission framework.
All actions are performed as the currently logged-in Confluence user.
The app respects Confluence’s native permission model at all times.
It does not access or expose data beyond what the user is authorized to view.
No privilege escalation or background access occurs.
4. Access Control
Access to secret data is governed by both Confluence permissions and app-level configuration.
Only users explicitly selected (or part of selected groups) can view the secret content.
Unauthorized users will not be able to see protected data.
Only users with edit permissions can configure or modify access settings.
View-only users cannot change configurations.
Group-based access is validated dynamically based on user membership.
5. Security Best Practices
To ensure secure usage of the app:
Share sensitive data only with trusted users or groups.
Avoid storing highly confidential information unless necessary and authorized.
Regularly review and update user/group access configurations.
Remove access for users who no longer require it.
Follow your organization’s internal data security policies when using this app.
6. License & Usage Enforcement
The app includes license validation to ensure authorized usage.
Features may be restricted if the license is inactive or invalid.
The app may prevent access to configuration or data when license validation fails.
License checks follow Atlassian Marketplace standards.
7. Vulnerability Reporting
We support responsible disclosure of security issues.
If you discover a potential vulnerability, please report it to: