Northwick

Security

Updated: 25 September 2026

Northwick is a small independent studio. This page says exactly how our Confluence Cloud apps are built and run, what we can and cannot see, and how to report a vulnerability. It says what is true today, not what we intend to do; where we have nothing, it says so.

Where the apps run

Every Northwick app is an Atlassian Forge app. It runs on Atlassian's infrastructure, inside your site's region. We operate no servers, no databases and no cloud accounts that hold your data, because there is nowhere for your data to go: the apps declare no external egress in their manifests, so they can call the Confluence API of your own site and nothing else. That is what the "Runs on Atlassian" badge on the Marketplace listing means, and it is the single largest security property of these apps.

There is no browser extension, no desktop agent, no webhook endpoint of ours, and no third-party analytics or advertising code in the apps.

What is stored, and where

App data lives in Forge storage, provided by Atlassian, in your site's region. The full field-by-field list is in the Privacy Policy and it is short: page and space identifiers, an Atlassian account ID for the person responsible, dates, versions, counts, and the app's own bookkeeping. No page content, no comments, no attachments, no names and no email addresses.

When you stop tracking a page, that page's record is deleted immediately. When you uninstall an app, Atlassian holds its storage for 28 days and then deletes it permanently; we cannot read or recover data in that window.

Who can see what

Logs

The apps write operational logs to Atlassian's logging service: page identifiers, an opaque installation identifier, counts and error messages. Account IDs are recorded only as "present" or "missing", and page content, names and email addresses are never logged. The logs stay inside Atlassian's infrastructure. We read them for two purposes only — to diagnose a failure, and to count per installation whether an app is in use — and never for advertising, and never shared with anyone. The Privacy Policy states the same in full.

How changes reach your site

Reporting a vulnerability

Email Northwick.apps@gmail.com with "Security" in the subject. Please include what you found, the steps to reproduce it, the app and version, and the approximate time. Never include credentials, tokens or customer data in the report.

What we commit to: we acknowledge a security report within one business day (Sunday to Thursday, Israel time), tell you what we have confirmed and what we are doing, and keep you updated until it is closed. We ask that you give us a reasonable chance to fix an issue before disclosing it publicly, and we will credit you by name if you want that. We do not run a paid bug bounty.

What we do not have

Saying this plainly is more useful to your review than a page of assurances:

Questions

Security questionnaires, architecture questions and procurement reviews go to Northwick.apps@gmail.com. We answer from the code, and if the answer is "the app cannot do that" or "we do not have that", we say so.