Security
We handle your Confluence content with care, because we know how sensitive internal documentation can be. Here’s exactly what we do and what we don’t yet do, so you can make an informed call. Region-specific points are at the end, under For EU residents and For non-EU residents.
What we do
- Encryption. Confluence content is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256 via AWS KMS).
- Data minimization. We keep a derived index (embedding vectors) and the short excerpts behind each finding – the quote, the affected block, and the titles of the pages the finding involves – not a full copy of your wiki. Full page bodies are dropped at the database layer and re-read live from Confluence each scan. One exception, and it exists so you can undo things: when you merge duplicate pages, the page you didn’t keep has its previous body stored, because that’s what a revert puts back. We write nothing back without your explicit approval, and content fixes revert in one click.
- Tenant isolation. Every database query is auto-filtered by PostgreSQL row-level security. One customer’s data is never reachable from another’s queries.
- Minimum-necessary scopes. We request more than “read and write pages”, so here is the whole shape of it: read the spaces you scope a report to, write to pages you choose to fix, post a comment when you ask a page owner to decide, read page metadata, and resolve directory information – users, groups, and the report owner’s email address – to work out who owns a page and where to send a scan email. The full list, with our rationale against each one, is public in the Forge manifest on our Marketplace listing – verify it rather than take our word for it.
- Encrypted credentials. Your Atlassian tokens and any AI key you bring are envelope-encrypted with AWS KMS (a KMS-managed data key plus local AES-256-GCM); the key rotates automatically. The plaintext never crosses a wire boundary and is never logged.
- No training on your data. Default inference runs on AWS Bedrock. Per AWS Bedrock’s terms, your prompts and completions are never used to train base models, and no model vendor has access to them – AWS is the inference subprocessor. If you bring your own Anthropic key, those calls go to Anthropic directly under your own agreement – see “Where we process your data.”
- Subprocessors. Every sub-processor that offers an EU region is configured to it, and each is governed by its standard data-processing terms. One does not offer an EU region: TypeSafe (System One classifier) processes in the US, and only installs that have not required EU residency reach it – see “Where we process your data”. Product analytics (PostHog) and error tracking (Sentry) receive metadata only – page titles, excerpts, and content are stripped by a code-enforced allow-list, with two deliberate exceptions we’d rather name than bury: your Atlassian site host, and the text of your own search-box queries. (Analytics for this marketing website collects different things – see the Privacy Policy.) The one exception is Langfuse (AI-quality monitoring): to monitor and improve answer quality it receives the full text we send to the AI model and the model’s response, which include the page content under review – so we pin it to an EU-resident instance. The full list, with each vendor’s purpose and location, is on our Sub-processors page; changes are published in advance to a feed you can follow.
Where we process your data
Customer data is stored in AWS Frankfurt (eu-central-1), and that is where storage, compute and default AI inference run. Inference runs on AWS Bedrock through an EU inference profile that stays within EU regions; cross-continent inference is blocked in code, and embeddings run in the same region. Some steps may instead run on Mistral’s EU endpoint in France, which is EU-resident too and enforced in code.
One step is the exception, on installs that have not required a region. Before WikiFix compares what two passages say, it confirms they are really talking about the same thing. That check is made by TypeSafe System One (the Jev classifier), whose endpoint processes in the United States; it receives the specific paragraphs being compared, with their page title, section and surrounding context – not whole pages, never the whole space. Require EU residency on the Residency tab in WikiFix Admin (see Data residency) and that check runs on Claude Sonnet on Bedrock in Frankfurt instead – every step then stays in the EU, and a scan that cannot meet that stops rather than quietly processing your content elsewhere. Sonnet costs materially more than Jev, so an install that requires EU residency spends more credits per scan. Today we run one region, and EU is the only residency we can serve.
The other path that leaves this setup is the one you choose: the optional bring-your-own-key path, available on a paid Advanced plan. If you configure your own Anthropic API key, those inference calls – both the scan and the rewrite that authors a fix – go to Anthropic’s API directly, outside the EU-region pin and under your own agreement with Anthropic.
Government access & legal reach
WikiFix is operated by Totem Dev, incorporated in Moldova. Where authorities can compel data, they reach it through the providers that hold it and through legal-assistance channels; our place of incorporation does not put it beyond reach.
- Your data sits with AWS, a US provider. AWS can be compelled under the US CLOUD Act wherever it stores data, including Frankfurt. AWS’s published commitments include challenging government data-access requests and notifying customers when legally permitted, but the legal reach exists.
- Authorities can ask Moldova for assistance. There’s no bilateral US–Moldova treaty, but both are parties to multilateral mutual-legal-assistance conventions – the Council of Europe Budapest Convention on Cybercrime, the UN Convention against Transnational Organized Crime, and the UN Convention against Corruption.
What actually protects your data is EU-region processing, data minimization, and encryption.
Data retention and deletion
We delete your data within 30 days of uninstall. This is automatic – a daily job purges tenants that passed the 30-day mark, whether or not you ask. The 30 days exist so a re-install picks up where you left off. Want it gone sooner? Email security@wikifix.ai. Database backups have a 7-day retention window.
What we don’t have yet
SOC 2 attestation. Not today. The audit alone costs $15,000+ and we won’t burn pre-revenue cash on it. We’ll engage an auditor once paying-customer revenue justifies the spend, likely 6 to 12 months after launch. If your procurement requires SOC 2 attestation today, we’re not the right fit yet. If our DPA plus the rest of this page covers your review, we’d love to talk. We answer custom security questionnaires within 3 business days.
EU-sovereign AI by default. Default inference runs via AWS Bedrock in Frankfurt. OpenAI’s gpt-oss-120b does the heavy lifting – it pulls the facts out of each page and authors the fix when you apply one – and it’s an open-weight model AWS hosts and serves itself, so no prompt is sent to OpenAI. Cohere Embed v4, also served by Bedrock, builds the index that decides which pages are worth comparing. Neither model vendor sees your prompts or completions; AWS is the inference sub-processor. Two caveats. The first is AWS itself – the inference stays in the EU, but the company serving it is US-incorporated. The second is the same-question check described under “Where we process your data”: on installs without an EU residency requirement it runs on TypeSafe System One in the US, a third-party vendor that does see the passages it checks. Requiring EU residency removes the second caveat, not the first – and moves that check to Claude Sonnet, which costs more credits per scan.
If you require an EU-incorporated model provider, we can run your indexing and analysis on Mistral (French, EU-incorporated, on its EU endpoint in France) on request – email security@wikifix.ai.
For EU residents
If you are in the EU or EEA, the GDPR applies and your organization is the data controller, with WikiFix (Totem Dev) acting as processor. Your data is stored in the EU (AWS Frankfurt), and with EU residency required for your install every step of the processing stays there too; without that requirement, one check runs in the US, as described under “Where we process your data”. Our GDPR-aligned Data Processing Agreement is published in full and applies automatically when you accept our Terms — nothing to request, negotiate or sign, though we’ll send a countersigned copy if your procurement process needs one. You may lodge a complaint with your national supervisory authority. Totem Dev’s home jurisdiction, Moldova, is itself bound by the Council of Europe Convention 108+ on data protection. Data-subject rights and how to exercise them are in our Privacy Policy.
For non-EU residents
Everything under What we do and Where we process your data applies to you unchanged: your data is hosted in the EU regardless of where you are, and we extend the same controls and protections to all customers. US residency is not something we can serve today – our infrastructure is pinned to Frankfurt, so a US requirement is refused honestly rather than served from the EU and called US. You can still record the requirement; scans stop until we can meet it. If full-stack, CLOUD-Act-free hosting on an EU-incorporated provider is a hard requirement, we’re not the right fit today; tell us at security@wikifix.ai if it’s a deal-driver. US residents: see the California/CPRA note in our Privacy Policy.
Reporting security issues
security@wikifix.ai. We acknowledge within 24 business hours. We credit researchers in our release notes and respond seriously.
Contact
Our DPA needs no signature – accepting the Terms accepts it. For a countersigned copy, custom questionnaires, or specific security questions: security@wikifix.ai.