Security

Chockablock builds Atlassian Confluence apps that never send your content anywhere. This page states how that is enforced, and how to report a vulnerability.

Last reviewed 21 August 2026. Reviewed annually, and after any security incident.

Reporting a vulnerability

Email [email protected] with SECURITY in the subject line. Include reproduction steps, and — if the issue concerns a specific document — whatever part of the specification you can share.

Please do not disclose publicly until a fix has shipped. Reporters who want credit will be credited.

What we hold

Nothing. We operate no servers, no database and no vendor-side storage, and we never receive your content. An API specification is read from Confluence macro configuration or a page attachment and rendered in the reader's own browser, inside your Atlassian site. No specification content, page content, credential or personal data is transmitted to us or to any third party at any point.

This is enforced by the platform rather than promised by this page. The app declares no external permissions, no remote resources and no web triggers, so Atlassian's own content security policy refuses outbound requests regardless of what the application code does. The app is eligible for Atlassian's Runs on Atlassian programme.

Permissions

The app requests exactly one OAuth scope — read:attachment:confluence, read-only — used solely to list a page's attachments and download the specification you selected. No other scope has ever been requested.

How untrusted content is handled

An API specification is untrusted input and is treated as such:

How releases are verified

Every change is gated by an automated suite that must pass before release: 939 automated tests; a corpus runner exercising the renderer against real-world specifications; an adversarial fixture corpus targeting the parser and sanitizer, including injection attempts; an egress harness that intercepts every network request during a full render and asserts zero non-Atlassian traffic; and a harness that parses sanitizer output with a real HTML parser and asserts zero live elements, event handlers or unsafe URLs.

Static analysis runs over the shipped source with the OWASP Top Ten, JavaScript and TypeScript rule sets. Dependencies are scanned continuously; the shipped app has two runtime dependencies, both published by Atlassian.

Continuity

The app runs on Atlassian's infrastructure, not ours, so its availability does not depend on ours. Because we hold no data, there is no customer data that can be lost. Recovery of the build from source is documented and exercised at least annually; it was last exercised on 21 August 2026.