IntelliGlossary — Security Policy
Last updated: 8 August 2026
This policy describes how LH Buyer Technology LLC protects IntelliGlossary for
Confluence Cloud and how to report a suspected vulnerability.
Reporting a vulnerability
Please report suspected vulnerabilities privately to
lhbuyertech@gmail.com rather than in a public
issue tracker. We aim to acknowledge reports within one business day.
Please include:
- A clear description of the issue and its impact.
- Reproduction steps, a proof of concept, or a sample payload.
- The Atlassian site URL and app version where you reproduced it.
- Whether you are an Atlassian tenant administrator, contributor, or third party.
We coordinate disclosure timelines with Atlassian's Marketplace security process and
the Atlassian Trust Center. Please allow a
reasonable window to triage and patch before public disclosure.
Security architecture
- The app runs inside the Atlassian Forge sandbox. Core app storage remains in Forge
KVS on the customer's tenant.
- Forge KVS data is encrypted at rest by Atlassian. The app does not operate an
out-of-tenant data store.
- The app has no Confluence page-write scope and no SMTP egress.
- Configured AI provider keys are stored in Forge encrypted secrets and are never
returned to the browser.
- AI egress is opt-in per installation. Requests contain only a short bounded page
excerpt and the term being drafted—not the full page, actor account ID, or user
identifier.
- Customer-configured AI endpoints require the Connected Apps consent flow and are
stored per installation.
- Resolver write operations enforce server-side role and scope checks.
- Audit entries record term, settings, and discovery changes with actor, scope,
timestamp, and reason.
AI provider transfer safeguards
AI is disabled by default. When enabled, data may be sent to the selected provider.
For provider-specific DPA, SCC, and international-transfer conditions, see the
International Data Transfer Safeguards register.
Out of scope
The following should be filed as normal support requests rather than security reports:
- Feature requests or behavior changes.
- Confluence platform issues unrelated to this app.
- Third-party AI provider outages.
- Performance, UI, or terminology-rule questions.
Privacy Policy ·
Terms of Use ·
IntelliGlossary User Manual