Definitive Glossary

Security policy

Last updated: October 2026

This policy describes how the Definitive Glossary app for Confluence Cloud ("the app") protects your data, and how to report a security problem. The app is provided by e360 ("we", "us"). How the app handles personal data is covered in the privacy policy.

Summary

Hosting and infrastructure

The app's code runs in Atlassian's Forge functions, and its data is kept in Atlassian's Forge hosted storage, tied to your site's installation of the app. Atlassian operates, secures and monitors that infrastructure; see the Atlassian Trust Center for its controls and certifications. The app declares no external domains, remote back ends or web triggers, so there is no route for data to leave Atlassian.

Data the app handles

The app's data is stored within Atlassian. The app does not yet support choosing a data residency location.

Access control

Authentication

Atlassian handles sign-in. The app has no accounts or passwords of its own, and never asks for API tokens or personal access tokens.

Logging

The app's logs, kept in Atlassian's Forge platform, record errors only. They don't contain glossary content or personal data.

Secure development

Reporting a vulnerability

If you find a security problem in the app, email support@definitiveglossary.com with "Security" in the subject. Please include the steps to reproduce it and don't share the details publicly until it's fixed. We acknowledge reports within one business day, keep you updated, and fix confirmed issues within the timeframes Atlassian sets for Marketplace apps.

Security incidents

If a security incident affects your data, we will notify you and Atlassian without undue delay, explain what happened and what we are doing about it, and follow up when it's resolved.

Retention and deletion

Glossary data is kept while the app is installed. Admins can export it to CSV and delete terms at any time. When the app is uninstalled, Atlassian handles the app's stored data under its Forge data retention policies. Weekly, the app reports stored account IDs to Atlassian and erases closed accounts from everything it stores.

Contact

Security contact: support@definitiveglossary.com