Tim Schartman

Security

Applies to Crosscheck for Confluence. Last updated 27 July 2026.

The architecture is the security control. Crosscheck declares no external network permissions. The Atlassian platform therefore prevents it from sending data outside the Atlassian environment — regardless of what the code attempts. This is enforced by the platform, not promised by me.

Runs on Atlassian

Crosscheck carries Atlassian's Runs on Atlassian badge, awarded only to apps that use exclusively Atlassian-hosted compute and storage and do not egress customer data. Eligibility is verified by Atlassian, not self-declared, and can be confirmed on the Marketplace listing.

For a security review, this means the usual vendor questionnaire is largely moot:

QuestionAnswer
Where is our data processed?Inside your Atlassian site, on Atlassian infrastructure
Where is it stored?Atlassian Forge storage, subject to your existing data residency configuration
Which sub-processors are used?None
Which third parties receive our data?None
Can the vendor read our content?No. No copy is transmitted outside Atlassian.
Is data used for model training?No
What happens on uninstall?All stored data is removed with the app installation

Permissions requested

Crosscheck requests read-only access. It cannot create, modify or delete any Confluence content.

There is no write scope of any kind. Personal spaces are excluded entirely and are never read.

AI processing

Contradiction detection uses the Atlassian Forge LLMs service, which runs Anthropic Claude models within the Atlassian platform. No API key of mine and no third-party AI provider is involved, and requests do not leave Atlassian's infrastructure.

Only short excerpts from the two pages under comparison are analysed — never whole spaces. On the free plan no model is called at all.

Authentication and access

Crosscheck holds no credentials of its own and has no login. It operates under the OAuth scopes your administrator approves at install, and access is revoked immediately on uninstall. There is no vendor-side account, dashboard or console that could be compromised, because none exists.

Data retention

Full details of what is and is not stored are in the privacy policy, which lists it item by item.

Reporting a vulnerability

Email support@timschartman.com with SECURITY in the subject line.

Please do not publicly disclose an unpatched issue before it has been addressed. Good faith research is welcomed and credited if you would like it to be.

Honest limitations

Crosscheck is maintained by one person. It holds no formal certification — no SOC 2, no ISO 27001 — and claiming otherwise would be false. What it offers instead is a much smaller attack surface than a typical vendor integration: no servers, no vendor-held credentials, no data leaving your instance, and no third parties in the chain.

If your procurement process requires a certified vendor, that is a legitimate reason not to adopt this app, and I would rather say so here than waste your review cycle.