Auditable is built on Atlassian Forge and runs entirely inside Atlassian's cloud infrastructure. We operate no servers of our own, and your content is never transmitted to us or to any third party. We cannot read your Confluence content.
Auditable stores the following in Atlassian's Forge storage, inside your own Atlassian cloud tenancy, subject to your site's data residency settings:
| Data | Purpose |
|---|---|
| Confluence page IDs, titles and space keys | Identify which pages are under document control |
| Atlassian account IDs of owners and approvers | Record who owns and who approved a document |
| Approval timestamps and page version numbers | Provide the audit record |
| SHA-256 hashes of approved page content | Detect whether a page changed after approval |
| Review dates and review intervals | Track when a document is next due for review |
| Free-text approval notes you enter | Context on the audit record |
We do not store names or email addresses. Only the opaque Atlassian account ID is recorded. Display names are resolved from Confluence at the moment you view a page or export a pack, and are never written to storage. The app therefore holds no personal data beyond an opaque user reference.
We do not store page content. Only a one-way SHA-256 hash of it, which cannot be reversed to recover the original text.
your own site.
| Scope | Why |
|---|---|
read:page:confluence | Read page content to compute the approval hash |
read:space:confluence | List spaces so you can select one for a control set |
read:user:confluence | Show approver and owner names instead of raw account IDs |
read:confluence-content.summary | Receive page-updated events to detect changes after approval |
storage:app | Store the records listed above |
All scopes are read-only with respect to your Confluence content. The app never modifies, creates or deletes any page.
Records persist while the app is installed. When you uninstall Auditable, Atlassian deletes all app storage associated with your site, in line with the Forge platform's data lifecycle.
Audit events are deliberately append-only while the app is installed — they are not edited or deleted by the app, because their integrity is the product's purpose. Removing a control set un-enrols its documents but retains their history.
Because all data is held within your own Atlassian tenancy, you remain the data controller. You can export every record the app holds at any time using the built-in evidence pack export (CSV and JSON), and you can erase all of it by uninstalling the app.
None. Atlassian is the sole infrastructure provider, acting under your existing agreement with them.
Material changes will be reflected here with an updated date, and noted in the app's release notes on the Atlassian Marketplace.
Questions about this policy: tanzeel@rethought.to