Read & Confirm ("the App") is a Confluence Cloud application built on Atlassian Forge. This Security Policy describes the security measures and architecture that protect your data.
Architecture & infrastructure
The App is built entirely on Atlassian Forge, a serverless platform that runs within Atlassian's own cloud infrastructure:
- Backend (resolvers): all server-side code executes within Atlassian's serverless environment — no external servers are involved
- Frontend: runs in a sandboxed iframe within the Confluence interface, isolated from other content
- Data storage: all data is stored in Forge Storage, managed and encrypted by Atlassian
- No external services: the App makes no outbound network requests to external servers or third-party services
Data protection
- Encryption: all data in Forge Storage is encrypted at rest by Atlassian's infrastructure, and all communications are encrypted using TLS/HTTPS
- Data isolation: data is scoped to each Confluence site installation, is never shared between customer installations, and never leaves Atlassian's infrastructure
- Data minimization: we collect only the minimum data required for confirmation tracking — user account IDs (to track who confirmed), confirmation timestamps, and request metadata (deadlines, messages, target settings)
Access control
- Any Confluence user with page editing permissions can create confirmation requests
- Users can view confirmation status for requests associated with pages they have access to
- All access is governed by Confluence's existing permission model
- The App requests only the minimum permission scopes necessary for its functionality
Permissions
The App requests only the minimum permissions necessary for its functionality, including reading page and user information for confirmation tracking and storing data via Forge Storage. See Atlassian's Forge documentation for details on how Forge manages app permissions and scopes.
Vulnerability management
- The App follows secure coding practices
- Dependencies are regularly reviewed and updated
- The Forge platform handles underlying infrastructure security, patching, and updates
Incident response
In the event of a security incident:
- We will investigate and assess the scope and impact promptly
- Corrective measures will be implemented and verified
- A post-incident review will be conducted to prevent recurrence
Compliance
- The App is designed to support GDPR and CCPA compliance requirements
- No personal data is transferred outside of Atlassian's infrastructure
- See our Privacy policy for details on data handling practices
Third-party audits & certifications
The App runs entirely within Atlassian's Forge infrastructure, which benefits from Atlassian's own security certifications, including SOC 2 and ISO 27001. For details, refer to Atlassian's Trust Center.
Changes to this policy
We may update this Security Policy from time to time. Changes will be posted on this page with an updated revision date.
Contact
If you have questions about this Security Policy, please contact:
MiddleCore
Email: contact@middle-core.com
This security policy is effective as of April 2026. Last updated: April 2026.