Security
Last updated: 9 September 2026
Hyperdella is a trading name of Hyperdella Pty Ltd (ACN 701 958 590 · ABN 48 701 958 590), registered in Australia. This page describes how our software is built and operated, and how to report a security problem. It is written to be checked, not to reassure.
Reporting a vulnerability
Email support@hyperdella.com. Put "security" in the subject line.
Tell us what you found, how to reproduce it, and what you were able to do with it. A proof of concept helps; a video is rarely necessary. If you would like a reply encrypted, say so and we will arrange it.
What to expect. We acknowledge reports within two business days and tell you what we intend to do about it. Hyperdella is a small company in Tasmania (UTC+10/+11), so a report filed late in the Australian week may be acknowledged the following Monday.
What we ask. Give us a reasonable chance to fix the issue before publishing it. Do not access, modify, or retain data belonging to anyone else while investigating, and do not degrade service for other users. We will not pursue legal action against anyone acting in good faith under these terms.
We do not currently run a paid bug bounty. We will credit you by name in the release notes if you would like us to.
Our Atlassian Marketplace apps
Sift is a Runs on Atlassian Forge app, which has a specific and verifiable meaning:
- All of its code executes on Atlassian's Forge platform, inside your own Atlassian cloud tenancy. Hyperdella operates no server that participates in running Sift.
- Sift makes no outbound network calls. Its manifest declares no external hosts and requests no egress permission, so there is no path by which your content could reach Hyperdella or any third party.
- Every Confluence read is performed as the person viewing, not as the app and not as the person who saved a query. Sift cannot show anyone a page they are not already permitted to read.
- What it stores — the saved queries you create, their per-user and per-space indexes, and your favourites — is held in Forge hosted storage inside your Atlassian tenancy, and inherits your site's data residency automatically.
- What it does not store: Confluence page content. Search results are fetched per request, rendered, and discarded.
- Uninstalling removes its stored data along with the installation, per Atlassian's Forge data-retention behaviour.
Sift requests five Atlassian scopes and no more: search:confluence,
read:confluence-content.summary, read:confluence-space.summary,
read:space:confluence and storage:app. It deliberately requests no permission to
read your user directory — which is why its "Created by" filter offers only "My pages"
and "Anyone's pages" rather than a list of your colleagues. We would rather not hold that
permission at all.
Sift never asks for Atlassian personal access tokens, account passwords, or any other shared secret. No Hyperdella app will ever ask you for one.
Our web services
Some Hyperdella products are ordinary web applications rather than Forge apps, and this site is one of them. For those:
- Transport is encrypted. Everything is served over HTTPS with certificates renewed automatically.
- Payments are handled by our payment provider. We never see or store full card details.
- Analytics are cookie-less and do not build a profile of you or follow you across the web.
- Data is backed up on a regular schedule, with restores exercised rather than assumed.
- Dependencies are scanned for known vulnerabilities on a weekly schedule, and patches for anything reachable are applied ahead of feature work.
What we do not claim
We would rather be checkable than impressive:
- Hyperdella holds no SOC 2, ISO 27001, HIPAA or FedRAMP certification. We are a small company and have not undertaken those audits. If your procurement process requires one, we are not currently a fit, and we would rather tell you now than at the end of a security review.
- We have not completed a CAIQ Lite questionnaire. Ask and we will answer specific questions directly.
- We run no paid bug bounty programme.
Contact
Security reports and questions: support@hyperdella.com
See also our privacy policy.