Security Policy — PageFlow

Last updated: March 10, 2026

Architecture

PageFlow is built on Atlassian Forge, a serverless sandboxed runtime. All data processing occurs within the Forge environment — no customer data is stored on external servers.

Data Handling

Access Control

Input Validation

Dependency Management

Vulnerability Reporting

Security issues can be reported to pageflow@adrianphilipp.de. We will acknowledge receipt within 48 hours and address confirmed vulnerabilities within the timeframes defined by Atlassian’s Marketplace security bug fix policy.

Incident Response

In case of a security incident, we will notify affected customers and Atlassian following the Marketplace incident communication guidelines.