A comprehensive overview of how we protect your data, handle security incidents, manage vulnerabilities, and the security controls we have in place for XPress.
Last updated: September 2026
XPress runs entirely within Atlassian's secure Forge platform - a sandboxed, multi-tenant environment with enterprise-grade security controls. Your data stays within the Atlassian cloud ecosystem.
XPress accesses Confluence content only when you initiate an action, and only through official Atlassian APIs.
We follow the principle of least privilege - XPress only requests the minimum API scopes necessary for its functionality. No unnecessary data access.
XPress sends usage events to an analytics service, filed under your Confluence site and including its address. They carry no account ID, no name or email address from anyone's Atlassian account, and no page content. Every event is sent from XPress's server side, and XPress loads no advertising or third-party tracking code in your browser.
How XPress accesses, processes, and stores data
When you initiate an export, XPress reads your Confluence pages through official Atlassian APIs within the Forge sandbox.
For a PDF export, document layout and styling are processed by our secure, cloud-hosted rendering service over encrypted HTTPS. An HTML export is produced within Forge and skips this step. The service processes data in-memory only and immediately discards all content - zero data retention.
Exported files, PDF or HTML, are stored in the Forge Object Store (Atlassian's cloud infrastructure) and deleted automatically after 30 days. They are never attached to your pages. All content reading and storage remains within the Atlassian environment.
| Data Type | Location | Retention | Encrypted |
|---|---|---|---|
| Exported files (PDF and HTML) | Forge Object Store (Atlassian cloud) | 30 days, then deleted automatically | ✅ At rest & in transit |
| Export history | Forge SQL (Atlassian cloud) | 30 days, then deleted automatically | ✅ At rest & in transit |
| Usage event counts (no account IDs, no content) | Forge SQL (Atlassian cloud) | Up to 4 days, then deleted automatically | ✅ At rest & in transit |
| Site logo and fonts you upload | Forge Object Store (Atlassian cloud) | Until removed or app uninstalled | ✅ At rest & in transit |
| App configuration and templates | Forge App Storage | Until app uninstalled | ✅ At rest & in transit |
Third-party services involved in data processing
| Service | Provider | Purpose | Data Location | Data Stored |
|---|---|---|---|---|
| Atlassian Forge | Atlassian | App runtime, SQL database, storage, queues | Per customer's Atlassian data residency | App config, templates, export history, exported files, usage event counts |
| Cloud Rendering Service | Amazon Web Services | Document rendering engine | United States | None - zero data retention |
| Usage Analytics | PostHog | Site-level usage events, with no account IDs and no page content | United States | Site cloud ID and address, event type and time, license status and type, XPress version, general values such as file format or a page-count range, and a daily summary of the site's setup and use, including how many people exported in the last 7 days as a range |
We do not use any other third-party services for data processing, analytics, or tracking within XPress.
Every permission explained
Measures we implement to protect your data
How we handle security incidents and vulnerabilities
Report a security issue: support@bytera.tech - Subject: "Security Incident" or "Vulnerability Report"
Support Portal: Bytera Support
| Phase | Action | Timeline |
|---|---|---|
| Acknowledgment | Confirm receipt and assign severity level | Within 24 hours |
| Triage | Assess scope, impact, and affected systems | Within 48 hours |
| Containment | Isolate affected components; disable features if necessary | Immediate upon confirmation |
| Remediation | Develop and deploy a fix | Based on severity |
| Notification | Notify affected customers with details and remediation steps | Within 72 hours of confirmation |
| Post-Mortem | Document root cause, lessons learned, and preventive measures | Within 2 weeks |
| Severity | Description | Target Resolution |
|---|---|---|
| Critical | Active exploitation, data breach, or complete service compromise | Within 24 hours |
| High | Vulnerability with significant impact potential but no active exploitation | Within 72 hours |
| Medium | Vulnerability with limited impact or requiring specific conditions | Within 1 week |
| Low | Minor issue with minimal security impact | Next scheduled release |
Our severity timelines align with the Atlassian Security Bug Fix Policy for Marketplace Partners.
Proactive and reactive security measures
We support responsible disclosure. If you discover a vulnerability, report it to support@bytera.tech before public disclosure. Allow reasonable time for investigation and patching. We will acknowledge your contribution (with your permission) once resolved.
Regulatory and platform compliance
Bytera operates as a data processor. We follow data minimization, purpose limitation, and respect data subject rights. Our rendering sub-processor (AWS) maintains GDPR compliance through Standard Contractual Clauses (SCCs).
XPress adheres to all Atlassian Marketplace Partner requirements for security, privacy, and the Security Bug Fix Policy.
By building on Forge, XPress inherits Atlassian's SOC 2 Type II certified infrastructure controls and benefits from their security-first platform architecture.
No. XPress accesses your content only during the export process. Exported files are stored in the Forge Object Store (Atlassian's infrastructure) for 30 days, but the original page content is never permanently copied or stored outside of Confluence.
During the export process, document layout and styling data is processed by our secure, cloud-hosted rendering service over encrypted HTTPS. This service operates as a stateless engine - it processes data in-memory only and immediately discards all content upon completion. The generated document is returned to Forge and no data is retained.
App data is hosted within Atlassian's Forge infrastructure, subject to your organization's Atlassian data residency settings. Our rendering service is hosted on secure cloud infrastructure in the United States.
Yes. We follow GDPR principles including data minimization, purpose limitation, and respect for data subject rights. Users can request data access, correction, or deletion at any time by contacting us.
When XPress is uninstalled, all app-related data (configuration, templates, export history and exported files) is automatically removed by the Atlassian Forge platform. No residual data remains.
Please contact us immediately at support@bytera.tech with the subject line "Security Concern". We take all security reports seriously and will respond within 24 hours.
We're committed to transparency. If you have any questions about our security practices, data handling, or need additional information for your security review, please don't hesitate to contact us.