Data & security

Trust center

This page sets out what our apps do with your data, what they are allowed to do, and what we commit to.

Illustration of document folders secured under a padlock inside a glass case, with a circular European Union emblem, representing data protection

Nothing leaves Atlassian. Our apps run entirely on Atlassian Forge, inside Atlassian's infrastructure. They declare no external egress, which means the platform itself blocks any outbound call to a server of ours or anyone else's. There is no Execolab server in the path; not for content, not for analytics.

No analytics, no tracking. We collect no usage data, and no telemetry is implemented in any published app.

No sub-processors. No third party processes your data on our behalf, because no data reaches us in the first place.

Where your data is

Content stays in your Confluence instance and follows the data residency you have configured with Atlassian.

App storage used by our apps is hosted by Atlassian as part of the Forge platform, and is governed by Atlassian's own terms. We do not choose or control its location independently.

Reporting a security issue

Write to security@execolab.com. We aim to acknowledge every report within 48 hours, keep you informed of our assessment, and credit you if you wish once the matter is resolved. Please do not open a public issue for a suspected vulnerability.

Encryption

Data in transit is encrypted with TLS 1.2+ (with Perfect Forward Secrecy); data at rest with AES-256. Neither is something we implement ourselves — both are inherited directly from the Atlassian Cloud infrastructure that Forge apps run inside, the same standard Atlassian applies to Jira and Confluence themselves.

How we build

Every change goes through automated linting, a full test suite, and a dependency vulnerability scan before it ships — all three run in CI on every commit, not just before a release. Permissions follow least privilege: each Atlassian scope our apps request is justified by a specific call that needs it, established by removing every scope and letting the platform state what it actually required, not by copying a common list. See Data & permissions for the exact scopes Multilingual Pages requests and why.

Privacy policy

The legal basis for everything on this page — what we process, why, and how to exercise your rights over it — is in our privacy policy.