Security
Northwick is a small independent studio. This page says exactly how our Confluence Cloud apps are built and run, what we can and cannot see, and how to report a vulnerability. It says what is true today, not what we intend to do; where we have nothing, it says so.
Where the apps run
Every Northwick app is an Atlassian Forge app. It runs on Atlassian's infrastructure, inside your site's region. We operate no servers, no databases and no cloud accounts that hold your data, because there is nowhere for your data to go: the apps declare no external egress in their manifests, so they can call the Confluence API of your own site and nothing else. That is what the "Runs on Atlassian" badge on the Marketplace listing means, and it is the single largest security property of these apps.
There is no browser extension, no desktop agent, no webhook endpoint of ours, and no third-party analytics or advertising code in the apps.
What is stored, and where
App data lives in Forge storage, provided by Atlassian, in your site's region. The full field-by-field list is in the Privacy Policy and it is short: page and space identifiers, an Atlassian account ID for the person responsible, dates, versions, counts, and the app's own bookkeeping. No page content, no comments, no attachments, no names and no email addresses.
When you stop tracking a page, that page's record is deleted immediately. When you uninstall an app, Atlassian holds its storage for 28 days and then deletes it permanently; we cannot read or recover data in that window.
Who can see what
- Every read and every change is permission-checked against Confluence, as you. Before an app shows or changes anything about a page, it asks Confluence whether your account may view or edit that specific page, and it fails closed: if the check errors, access is refused rather than granted. Page restrictions and space permissions therefore decide what each person sees, with nothing extra to configure.
- Background work runs as the app, never as a person, and is limited to what the app's declared scopes allow.
- Scopes are declared per call and kept minimal. Each scope in the manifest names the single API call that needs it. Adding one is a new major version of the app: Atlassian then requires every site to re-consent before the new version runs.
- Northwick staff have no access to your site. We cannot read your pages, your users or your app data; we see only what you send us in a support request.
Logs
The apps write operational logs to Atlassian's logging service: page identifiers, an opaque installation identifier, counts and error messages. Account IDs are recorded only as "present" or "missing", and page content, names and email addresses are never logged. The logs stay inside Atlassian's infrastructure. We read them for two purposes only — to diagnose a failure, and to count per installation whether an app is in use — and never for advertising, and never shared with anyone. The Privacy Policy states the same in full.
How changes reach your site
- Every change is a small commit with unit tests that must pass before it is merged; the test suite runs on every push.
- Deployments are made by continuous integration, never from a personal machine. The credentials that deploy our apps exist only as repository secrets; no person copies them anywhere.
- Code reaches a development environment first, then a staging copy, and only then production, which is what the Marketplace serves you.
- Every change is reviewed by an independent automated reviewer on a fixed schedule, and its findings are triaged under written service levels: a decision with evidence, then a fix or a tracked follow-up. Security findings are fixed before the next production deploy.
Reporting a vulnerability
Email Northwick.apps@gmail.com with "Security" in the subject. Please include what you found, the steps to reproduce it, the app and version, and the approximate time. Never include credentials, tokens or customer data in the report.
What we commit to: we acknowledge a security report within one business day (Sunday to Thursday, Israel time), tell you what we have confirmed and what we are doing, and keep you updated until it is closed. We ask that you give us a reasonable chance to fix an issue before disclosing it publicly, and we will credit you by name if you want that. We do not run a paid bug bounty.
What we do not have
Saying this plainly is more useful to your review than a page of assurances:
- No SOC 2 report, no ISO 27001 certificate and no third-party penetration test. Northwick is a one-person studio; those come with scale, and we will not imply them before they exist.
- No standard Data Processing Agreement is published. If your procurement requires one, write to us and say what it must cover.
- No uptime guarantee of our own: the apps run entirely on Atlassian's platform, so their availability is Atlassian's, and there is no service of ours to fall over.
- No subprocessors that touch app data. Atlassian hosts everything the apps store. Support correspondence arrives in a Google-hosted mailbox, so anything you choose to put in an email to us is held there.
Questions
Security questionnaires, architecture questions and procurement reviews go to Northwick.apps@gmail.com. We answer from the code, and if the answer is "the app cannot do that" or "we do not have that", we say so.