Security & Runs on Atlassian

Designed so customer Confluence content does not leave the Atlassian trust boundary for core product functions.

Runs on Atlassian

  • Compute: Forge functions on Atlassian infrastructure
  • Data at rest for app state: Forge KVS / entities
  • No arbitrary outbound HTTP from product resolvers
  • Marketing site is separate and does not receive page bodies

Permissions (minimum practical set)

Read Confluence content/space/user metadata; write limited content for optional review comments; storage:app for ownership and review records. Scope changes after Marketplace listing will be minimized.

Customer controls

Site admins install/uninstall the app. Uninstall removes access; request data deletion through support if needed after retirement.

Honesty note

Platform risk remains: Atlassian may change Forge quotas, APIs, or ship overlapping native features. Our business plan encodes stop-loss gates for that scenario.