Security
Approval Seal for Confluence runs entirely inside Atlassian's cloud, on the Atlassian Forge platform. There are no servers of ours involved, and the app makes no network calls outside Atlassian.
Where your data lives
All state is written to Forge's key-value storage, inside your own Atlassian environment. Nothing is copied out of it.
| Stored | Not stored |
|---|---|
| Page ID, space key | Page content or body text |
| Page version numbers | Attachments |
| Approval status and dates | Email addresses, names, avatars |
| Atlassian account IDs of the requester and approver | Passwords, tokens, API keys |
The account ID is Atlassian's own opaque user identifier. Approval Seal does not resolve it to a name or an email address; your Confluence site renders the person for display.
What the app can and cannot do
It requests three scopes, and all of them are read-only or storage-only:
read:confluence-content.summary— to receive the page-updated eventread:page:confluence— to read a page's current version numberstorage:app— its own approval records
The app requests no write access to your content. It cannot create, edit, move or delete pages, and it cannot read page bodies.
No egress, no third parties
- No external servers, databases or analytics
- No third-party services or sub-processors
- No data shared with anyone, in logs or otherwise
- No personal access tokens, passwords or shared secrets are ever requested
Access by Bobook Limited
We cannot read your approval records. Forge app storage is scoped to your own installation, and we have no mechanism to query it. Diagnosing a support issue relies on what you choose to tell us — which is why the support page asks for page IDs and version numbers rather than content.
Reporting a vulnerability
Email support@bobook.club with SECURITY in the subject line. We aim to
acknowledge within one business day. Please give us a reasonable opportunity to
respond before disclosing publicly.
What we do not claim
Being straight about this, because a security reviewer will ask:
- Approval Seal holds no compliance certifications — not ISO 27001, not SOC 2, not any other.
- No CAIQ Lite questionnaire has been completed yet.
- The app provides features your own validated process can use. It does not certify your organisation against any standard.
The strongest security statement we can make is architectural rather than procedural: the app has no infrastructure of its own to compromise, and no route by which your data could leave Atlassian.
Approval Seal