Security

Last updated: 9 September 2026

Hyperdella is a trading name of Hyperdella Pty Ltd (ACN 701 958 590 · ABN 48 701 958 590), registered in Australia. This page describes how our software is built and operated, and how to report a security problem. It is written to be checked, not to reassure.

Reporting a vulnerability

Email support@hyperdella.com. Put "security" in the subject line.

Tell us what you found, how to reproduce it, and what you were able to do with it. A proof of concept helps; a video is rarely necessary. If you would like a reply encrypted, say so and we will arrange it.

What to expect. We acknowledge reports within two business days and tell you what we intend to do about it. Hyperdella is a small company in Tasmania (UTC+10/+11), so a report filed late in the Australian week may be acknowledged the following Monday.

What we ask. Give us a reasonable chance to fix the issue before publishing it. Do not access, modify, or retain data belonging to anyone else while investigating, and do not degrade service for other users. We will not pursue legal action against anyone acting in good faith under these terms.

We do not currently run a paid bug bounty. We will credit you by name in the release notes if you would like us to.

Our Atlassian Marketplace apps

Sift is a Runs on Atlassian Forge app, which has a specific and verifiable meaning:

Sift requests five Atlassian scopes and no more: search:confluence, read:confluence-content.summary, read:confluence-space.summary, read:space:confluence and storage:app. It deliberately requests no permission to read your user directory — which is why its "Created by" filter offers only "My pages" and "Anyone's pages" rather than a list of your colleagues. We would rather not hold that permission at all.

Sift never asks for Atlassian personal access tokens, account passwords, or any other shared secret. No Hyperdella app will ever ask you for one.

Our web services

Some Hyperdella products are ordinary web applications rather than Forge apps, and this site is one of them. For those:

What we do not claim

We would rather be checkable than impressive:

Contact

Security reports and questions: support@hyperdella.com

See also our privacy policy.