Security and data
Runs on Atlassian
Apifolio is built on Atlassian Forge and is eligible for Runs on Atlassian: the app has no external servers and does not send data outside Atlassian. Its code runs on Atlassian's infrastructure, and your data stays under Atlassian's security, compliance and data-residency controls.
How data flows
- A reader opens a page. Apifolio, running in a sandboxed frame inside Confluence, asks Confluence for the spec file as that reader. If they can't see the file, they can't see the docs.
- The file is parsed and rendered in the reader's browser.
- For PDF/Word exports, the Rovo agent and anonymous visitors, Apifolio functions read the same file on Atlassian's infrastructure. Exports and agent answers use the current user's permissions; the anonymous fallback only serves files attached to the page being viewed.
- The Pro tools work in the browser too: version comparison downloads earlier versions of the file and the API catalog uses Confluence search, both as the current user.
Nothing is stored outside Confluence. The macro settings live in the page; the search digest (endpoint paths and summaries) is stored in the macro.
Permissions (scopes)
| Scope | Why Apifolio needs it |
|---|---|
read:page:confluence |
Read page titles and the macro settings in pages (agent and export) |
read:blogpost:confluence |
The same for blog posts |
read:attachment:confluence |
Read the spec files attached to pages |
write:attachment:confluence |
Save an uploaded or pasted spec as an attachment, only when an editor asks |
read:content-details:confluence |
Download attachment contents |
search:confluence |
Let the Rovo agent and the API catalog find pages with API docs, as the current user |
Safe rendering
Spec files are treated as untrusted input:
- Markdown in descriptions is sanitised (no scripts, frames, forms or styles); external images are shown as links;
- code and examples are rendered as text, never as HTML;
- parsing has size and depth limits, and is protected against hostile YAML (alias bombs) and prototype pollution;
- external
$reffiles and URLs are never fetched.
No credentials, no live calls
Apifolio has no "Try it out" button. It never stores API keys or tokens and never calls the APIs it documents. Code samples use placeholders such as YOUR_TOKEN.
Reporting a vulnerability
Write to [email protected] with the details and steps to reproduce. We acknowledge reports within 1 business day and fix confirmed issues within the timelines set by Atlassian's security requirements for Marketplace apps (critical within 10 days, high within 4 weeks, medium within 12 weeks, low within 25 weeks). Please don't disclose the issue publicly before it is fixed.