Security Policy — Space Roles Manager

Last updated: 23 June 2026

This page describes how the Lumas Forgery team ("we", "us") secures Space Roles Manager — an Atlassian Forge app for Confluence Cloud — and how to report a security issue.

1. Architecture and hosting

Space Roles Manager is a "Runs on Atlassian" Forge app. It runs entirely within Atlassian's Forge platform; we operate no servers, databases, or infrastructure of our own. The underlying compute, network, storage, runtime isolation, patching, and physical security are therefore managed by Atlassian under their security program. The app makes no network calls to systems outside Atlassian's cloud (no external egress).

2. Reporting a security issue

If you discover a security vulnerability in Space Roles Manager, please report it to security@lumasforgery.com. Please include steps to reproduce, the affected area, and the potential impact. We ask that you give us a reasonable opportunity to remediate before any public disclosure, and that your testing does not access, modify, or destroy data belonging to others, or degrade the service. We do not currently operate a paid bug-bounty program, but we are grateful for responsible disclosure.

3. Vulnerability management

4. Security incident handling

If a security incident affects the app, our process is to:

  1. Contain — deploy a fix or, where necessary, request that the affected app version be disabled.
  2. Assess — determine the scope, the data involved, and the impact.
  3. Remediate & verify — ship and confirm the fix.
  4. Notify — inform affected customers and Atlassian as required, and cooperate with Atlassian's security team throughout.

5. Technical and organizational controls

Access control and authorization

Data protection

Monitoring and logging

Secure development

6. Shared responsibility

Platform-level security — infrastructure, networking, physical security, runtime isolation, and storage encryption — is provided by Atlassian under their security and compliance programs (see the Atlassian Trust Center). Our responsibility covers the security of the app's code, configuration, requested scopes, and our handling of vulnerability reports and incidents.

7. Security contact

security@lumasforgery.com