MiddleCore/Products/Inkwell/Security policy
Inkwell icon
INK · Confluence Security policy

Security Policy

How Inkwell protects your data. Last updated: August 2026.

Inkwell ("the App") is a Confluence Cloud application built on Atlassian Forge. This Security Policy describes how we protect your data.

Architecture & infrastructure

The App is built entirely on Atlassian Forge, running within Atlassian's cloud infrastructure with no external servers or third-party services. The App has zero egress — it makes no outbound network requests outside of Atlassian's environment.

Data protection

  • Encryption: data in Forge Storage is encrypted at rest (AES-256). All communications use TLS 1.2+
  • Data isolation: data is namespaced per site installation and never shared between customers
  • Data minimization: the App stores only section tracking data (titles, instructions, statuses, due dates, assignee/reviewer references, and cached display names) and aggregate AI usage counters. It does not store Confluence page body content
  • Data lifecycle: all app data is automatically deleted by the Forge platform 28 days after uninstallation. Personal data of closed Atlassian accounts is erased via Atlassian's personal data reporting cycle

Access control

  • Users can only see sections on pages they have permission to view
  • Confluence page edit permission is a prerequisite for adding sections and participating in the workflow
  • Workflow actions (start, submit, approve, request changes) are additionally verified server-side against the user's role (page owner, section creator, assignee, reviewer) — the UI is not the security boundary
  • Status transitions are only possible through dedicated, validated endpoints; approved sections are locked from editing
  • The App never handles user credentials directly

Permissions

The App requests only the minimum scopes necessary for its features: reading page, space, and user information; writing reminder comments; updating page content only when you explicitly insert a Draft with AI result; and app storage. See Atlassian's Forge documentation for details.

AI features

  • Draft with AI and AI Digest run on Atlassian-hosted models via Forge LLMs — no external AI providers are used, preserving the App's zero-egress posture
  • Prompts and generated output are processed entirely within Atlassian's infrastructure
  • AI-generated drafts are written to a page only on an explicit user action (Append or Replace), on sections the user holds
  • AI generations draw from a per-site monthly allowance; aggregate usage is visible to the team under Team usage
  • Site administrators can disable the AI features for the entire site

Monitoring

  • Application logs and errors are monitored through the Forge developer console
  • Logs are reviewed regularly to detect anomalies or unexpected behavior
  • Infrastructure-level monitoring is provided by the Forge platform

Vulnerability management

  • Reporting: if you believe you have found a security vulnerability in the App, please report it to contact@middle-core.com. We will acknowledge your report within 2 business days
  • Triage: reported issues are assessed for severity and potential impact on customer data, and prioritized accordingly
  • Remediation: confirmed vulnerabilities are remediated based on severity, with critical issues addressed with the highest priority. Fixes are deployed through the Forge platform, which distributes updates to all installations
  • Dependencies are regularly reviewed and updated
  • The App has completed Atlassian's Marketplace security review process
  • The Forge platform manages infrastructure-level security and patching

Incident response

In the event of a security incident:

  1. We will investigate and assess the scope and impact promptly
  2. If customer data is affected, we will notify affected customers and report the incident to Atlassian without undue delay
  3. Corrective measures will be implemented and verified
  4. A post-incident review will be conducted to prevent recurrence

Compliance

  • The App is designed to support GDPR and CCPA compliance requirements
  • No personal data leaves Atlassian's infrastructure
  • The App implements Atlassian's personal data reporting requirements for Forge apps
  • See our Privacy policy for details

Third-party audits & certifications

The App runs on Atlassian's Forge platform, which is SOC 2 Type II attested and ISO 27001 certified. For details, refer to Atlassian's Trust Center.

Changes to this policy

We may update this Security Policy from time to time. Changes will be posted on this page with an updated revision date.

Contact

MiddleCore
Email: contact@middle-core.com

This security policy is effective as of August 2026. Last updated: August 2026.