Security
We handle your Confluence content with care, because we know how sensitive internal documentation can be. Here’s exactly what we do and what we don’t yet do, so you can make an informed call. Region-specific points are at the end, under For EU residents and For non-EU residents.
What we do
- Encryption. Confluence content is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256 via AWS KMS).
- Data minimization. We keep a derived index (embedding vectors) and the short excerpts behind each finding – the quote, the affected block, and the titles of the pages the finding involves – not a full copy of your wiki. Full page bodies are dropped at the database layer and re-read live from Confluence each scan. One exception, and it exists so you can undo things: when you merge duplicate pages, the page you didn’t keep has its previous body stored, because that’s what a revert puts back. We write nothing back without your explicit approval, and content fixes revert in one click.
- Tenant isolation. Every database query is auto-filtered by PostgreSQL row-level security. One customer’s data is never reachable from another’s queries.
- Minimum-necessary scopes. We request more than “read and write pages”, so here is the whole shape of it: read the spaces you scope a report to, write to pages you choose to fix, post a comment when you ask a page owner to decide, read page metadata, and resolve directory information – users, groups, and the report owner’s email address – to work out who owns a page and where to send a scan email. The full list, with our rationale against each one, is public in the Forge manifest on our Marketplace listing – verify it rather than take our word for it.
- Encrypted credentials. Your Atlassian tokens and any AI key you bring are envelope-encrypted with AWS KMS (a KMS-managed data key plus local AES-256-GCM); the key rotates automatically. The plaintext never crosses a wire boundary and is never logged.
- No training on your data. Default inference runs on AWS Bedrock. Per AWS Bedrock’s terms, your prompts and completions are never used to train base models, and no model vendor has access to them – AWS is the inference subprocessor. If you bring your own Anthropic key, those calls go to Anthropic directly under your own agreement – see “Where we process your data.”
- Subprocessors. Every sub-processor is configured to its EU region and governed by its standard data-processing terms. Product analytics (PostHog) and error tracking (Sentry) receive metadata only – page titles, excerpts, and content are stripped by a code-enforced allow-list, with two deliberate exceptions we’d rather name than bury: your Atlassian site host, and the text of your own search-box queries. (Analytics for this marketing website collects different things – see the Privacy Policy.) The one exception is Langfuse (AI-quality monitoring): to monitor and improve answer quality it receives the full text we send to the AI model and the model’s response, which include the page content under review – so we pin it to an EU-resident instance, the same as everything else. The full list, with each vendor’s purpose and location, is on our Sub-processors page; changes are published in advance to a feed you can follow.
Where we process your data
Customer data – including LLM prompts and completions – is processed in AWS Frankfurt (eu-central-1): storage, compute, and default AI inference. Inference runs on AWS Bedrock through an EU inference profile that stays within EU regions; cross-continent inference is blocked in code, and embeddings run in the same region. Some steps may instead run on Mistral’s EU endpoint in France, which is EU-resident too and enforced in code. We run a single region and don’t offer hosting in other geographies.
The one path that leaves this setup is the one you choose: the optional bring-your-own-key path, available on a paid Advanced plan. If you configure your own Anthropic API key, those inference calls – both the scan and the rewrite that authors a fix – go to Anthropic’s API directly, outside the EU-region pin and under your own agreement with Anthropic.
Government access & legal reach
WikiFix is operated by Totem Dev, incorporated in Moldova. Where authorities can compel data, they reach it through the providers that hold it and through legal-assistance channels; our place of incorporation does not put it beyond reach.
- Your data sits with AWS, a US provider. AWS can be compelled under the US CLOUD Act wherever it stores data, including Frankfurt. AWS’s published commitments include challenging government data-access requests and notifying customers when legally permitted, but the legal reach exists.
- Authorities can ask Moldova for assistance. There’s no bilateral US–Moldova treaty, but both are parties to multilateral mutual-legal-assistance conventions – the Council of Europe Budapest Convention on Cybercrime, the UN Convention against Transnational Organized Crime, and the UN Convention against Corruption.
What actually protects your data is EU-region processing, data minimization, and encryption.
Data retention and deletion
We delete your data within 30 days of uninstall. This is automatic – a daily job purges tenants that passed the 30-day mark, whether or not you ask. The 30 days exist so a re-install picks up where you left off. Want it gone sooner? Email security@wikifix.ai. Database backups have a 7-day retention window.
What we don’t have yet
SOC 2 attestation. Not today. The audit alone costs $15,000+ and we won’t burn pre-revenue cash on it. We’ll engage an auditor once paying-customer revenue justifies the spend, likely 6 to 12 months after launch. If your procurement requires SOC 2 attestation today, we’re not the right fit yet. If our DPA plus the rest of this page covers your review, we’d love to talk. We answer custom security questionnaires within 3 business days.
EU-sovereign AI by default. Default inference runs via AWS Bedrock in Frankfurt. OpenAI’s gpt-oss-120b does three jobs – it pulls the facts out of each page, judges whether pages actually disagree, and authors the fix when you apply one – and it’s an open-weight model AWS hosts and serves itself, so no prompt is sent to OpenAI. Cohere Embed v4, also served by Bedrock, builds the index that decides which pages are worth comparing. Neither model vendor sees your prompts or completions; AWS is the inference sub-processor. The caveat is AWS itself – the inference stays in the EU, but the company serving it is US-incorporated.
If you require an EU-incorporated model provider, we can run your indexing and analysis on Mistral (French, EU-incorporated, on its EU endpoint in France) on request – email security@wikifix.ai.
For EU residents
If you are in the EU or EEA, the GDPR applies and your organization is the data controller, with WikiFix (Totem Dev) acting as processor. Your data is processed in the EU (AWS Frankfurt) and every sub-processor is pinned to its EU region. Our GDPR-aligned Data Processing Agreement is published in full and applies automatically when you accept our Terms — nothing to request, negotiate or sign, though we’ll send a countersigned copy if your procurement process needs one. You may lodge a complaint with your national supervisory authority. Totem Dev’s home jurisdiction, Moldova, is itself bound by the Council of Europe Convention 108+ on data protection. Data-subject rights and how to exercise them are in our Privacy Policy.
For non-EU residents
Everything under What we do and Where we process your data applies to you unchanged: your data is hosted in the EU regardless of where you are, and we extend the same controls and protections to all customers. We don’t offer US or other-region residency – a single jurisdictional surface keeps our posture clean, and the ~100ms latency is rounding error against an asynchronous scan. If full-stack, CLOUD-Act-free hosting on an EU-incorporated provider is a hard requirement, we’re not the right fit today; tell us at security@wikifix.ai if it’s a deal-driver. US residents: see the California/CPRA note in our Privacy Policy.
Reporting security issues
security@wikifix.ai. We acknowledge within 24 business hours. We credit researchers in our release notes and respond seriously.
Contact
Our DPA needs no signature – accepting the Terms accepts it. For a countersigned copy, custom questionnaires, or specific security questions: security@wikifix.ai.