attachmentAV for Atlassian Confluence: Security

attachmentAV for Atlassian Confluence is secure by default. When you upload an attachment, our scanners are notified, download the attachment, scan it, and delete it. We don’t keep a copy of your data.

Jurisdiction (#)

attachmentAV for Atlassian Confluence scans attachments (process your data) in the jurisdiction/region/location of your choice to help you meet data residency requirements.

To choose a jurisdiction, follow Atlassian Support.

Permissions (#)

OAuth 2.0 scopes (#)

attachmentAV for Atlassian Confluence requests the following OAuth 2.0 scopes during installation to access your Confluence instance:

CategoryScopeAtlassian descriptionattachmentAV description
Forge platform scopestorage:appEnables the App storage API.to store scan results & configuration on the Atlassian platform
Forge platform scoperead:app-system-tokenEnables Forge to pass a token to a remote backend, that can be used to invoke Atlassian product REST APIs with the permissions of the app “bot” user.to run the full scan outside of Forge on our backend
Confluence granular scoperead:attachment:confluenceView and download content attachmentsto list attachments in backend & get download URL for attachment
Confluence granular scoperead:custom-content:confluenceView custom contentto get space id for custom content id in backend
Confluence granular scoperead:label:confluenceView labelsto add labels to attachments
Confluence granular scoperead:page:confluenceView pagesto get space id for page id & blogpost id in backend
Confluence granular scoperead:space:confluenceView spacesto get space key for space id in backend
Confluence granular scopedelete:attachment:confluenceDelete content attachmentsto delete infected/unscannable attachments
Confluence granular scopewrite:comment:confluenceCreate and update commentsto add a comment to a page
Confluence granular scopewrite:label:confluenceAdd and remove labelsto add labels to attachments
Confluence classic scopesread:confluence-content.summaryRead Confluence content summaryrequired by events avi:confluence:created:attachment & avi:confluence:updated:attachment to trigger real-time scans

Confluence permissions (#)

Confluence provides a second layer of permissions called content-level permissions. If you use content-level permissions, ensure that attachmentAV has appropriate access.

Space permissions (#)

In your space settings, go to user access.

Space settings

Check if attachmentAV has permissions to view all content, add comments, and delete attachments.

Space access

Page restrictions (#)

A page is restricted if you can see the lock icon at the top right Restricted page.

Click on the icon to see the details. Expand the Specific access section to check if attachmentAV has edit permissions.

View page permissions

If attachmentAV is missing in the list, search for attachmentAV and select the attachmentAV app.

Add page permissions: step 1

Ensure that the permissions are set to Can edit and click Share.

Add page permissions: step 2

Encryption (#)

In transit (#)

All network communication is TLS encrypted using HTTPS.

At rest (#)

Your attachments are temporarily stored on encrypted disks on our scanners. Attachments are deleted right after the scan.

Need more help?

Write us, and we'll get back to you as soon as we can.

Send us an email