Policy
1. Data Security
All data submitted through the Sitemap Renderer app (such as sitemap XML content) is securely stored within the Atlassian ecosystem.
No data is stored or transmitted outside Confluence or the Atlassian infrastructure.
The app does not collect, process, or transmit any personally identifiable information (PII) unless explicitly included by the user within the submitted sitemap XML content.
2. Content Restrictions
This app enables users to render sitemap XML data within Confluence.
To protect users and maintain platform security:
Only valid sitemap XML content should be provided.
No custom scripts, JavaScript execution, or dynamic code injection is supported.
XML content is parsed strictly for URL, priority, and last modified metadata.
Rendering is governed by the browser’s security model and Atlassian’s Content Security Policy (CSP).
Malicious, malformed, or unauthorized XML content may result in rendering failure.
3. Authentication & Permissions
The app runs in the context of the currently authenticated Confluence user.
It fully respects Atlassian’s permission model and does not access, modify, or expose any data beyond what the user is explicitly authorized to view or configure.
4. Access Control
Only Confluence users with appropriate page view and edit permissions can view or configure sitemap data.
The configuration interface is available only in edit mode.
Unauthorized users cannot modify or delete sitemap configurations.
Users with view-only access can see the rendered Table View and Layer View but cannot change the configuration.
5. Security Best Practices
To maintain a secure experience while using the Sitemap XML Viewer:
Provide only trusted and verified sitemap XML content.
Avoid uploading XML from unknown or untrusted sources.
Ensure the sitemap data complies with your organization’s security and data policies.
Periodically review configured sitemap content for accuracy and relevance.
6. Vulnerability Reporting
We welcome responsible disclosure of any potential security vulnerabilities.
Please report any concerns to:
📧 developer@alvanium.com