Prometheus

Prometheus Agency — Security Policy

Effective date: July 17, 2026 · Applies to all Prometheus Agency apps on the Atlassian Marketplace, including Access Lens — Permissions Audit for Confluence and Answers — Q&A for Confluence.

This page describes how we, as the vendor, secure our apps and the systems used to build and operate them. For how each app handles your data, see the app's Privacy Policy (Access Lens · Answers).

1. Architecture: everything runs inside Atlassian

Our apps are built on Atlassian Forge and designed to meet the requirements of Atlassian's Runs on Atlassian program:

This architecture deliberately minimizes the attack surface: there is no vendor-side system holding your data that could be breached.

2. Secure development practices

3. Access controls on our side

4. Vulnerability management

5. Reporting a vulnerability (responsible disclosure)

We welcome reports from security researchers and customers. If you believe you have found a security issue in any of our apps:

6. Security incident response

If we become aware of a security incident affecting one of our apps:

Note that because our apps store no customer data on vendor-side systems (see section 1), the realistic incident surface is limited to defects in app code; there is no vendor database whose breach could expose your content.

7. Data handling summary

8. Changes to this policy

If our security practices change, we will update this page and, where relevant, the apps' Marketplace listings before the change takes effect.

9. Contact

Security questions or reports: info@prometheus-agency.com (subject “SECURITY”) · Support page