Security & Runs on Atlassian
Designed so customer Confluence content does not leave the Atlassian trust boundary for core product functions.
Runs on Atlassian
- Compute: Forge functions on Atlassian infrastructure
- Data at rest for app state: Forge KVS / entities
- No arbitrary outbound HTTP from product resolvers
- Marketing site is separate and does not receive page bodies
Permissions (minimum practical set)
Read Confluence content/space/user metadata; write limited content for optional review comments; storage:app for ownership and review records. Scope changes after Marketplace listing will be minimized.
Customer controls
Site admins install/uninstall the app. Uninstall removes access; request data deletion through support if needed after retirement.
Honesty note
Platform risk remains: Atlassian may change Forge quotas, APIs, or ship overlapping native features. Our business plan encodes stop-loss gates for that scenario.