These policies describe what MIKSUMIA actually does today to protect the
“Miksumia Publisher” application and its customers' data. MIKSUMIA is a
one-person company. Vulnerability reporting and incident response are
detailed on the security page.
1. Scope and governance
These policies cover the “Miksumia Publisher” application and the
miksumia.com website. One person, the founder, owns security.
These policies are reviewed at least once a year and after any major change
to the application. Last review: 6 October 2026. Our answers to the Cloud
Security Alliance CAIQ Lite v4.1.0 questionnaire are published here:
CAIQ Lite v4.1.0 (xlsx),
and listed on the CSA STAR registry (STAR Level One, self-assessment).
2. Risk management
- Security is reviewed at each release.
- Automated tests run on every change.
- Dependencies are audited for published vulnerabilities every week.
- Code goes through review loops before each release, repeated until a
round finds no real defect.
- Known limits of the application are written down.
3. Access control
- Only the founder has access to production, the source code, and the
Google Cloud and Atlassian developer accounts.
- Two-factor authentication protects the Atlassian, Google and GitHub
accounts.
- The application requests the narrowest OAuth scopes it needs. Google
Drive is read-only.
- Configuring the application is reserved to Confluence site
administrators. This is checked on each request.
4. Encryption and secrets
- All communications use HTTPS.
- Application secrets and Google tokens are kept in the encrypted secrets
store of Atlassian Forge.
- Secrets never appear in the source code or in logs.
- A leaked or suspected secret is revoked and replaced the same day.
5. Supplier management
MIKSUMIA uses two sub-processors:
- Atlassian: hosting and storage of the application
(Forge).
- Google: Drive, Sheets, Slides, OAuth authorisation and
Gemini API.
They were chosen for their published security programmes. They are listed
in the privacy policy. The list is reviewed at
the annual policy review.
6. Business continuity and recovery
- MIKSUMIA runs no server of its own.
- Hosting, storage, availability and backups are provided by Atlassian
Forge, as described in its
shared responsibility model.
- The source code is kept in GitHub, with its history.
- The application can be redeployed from its source code.
- Pages already published belong to the customer and stay in their
Confluence site.
7. Vulnerability and incident management
- Reports go to contact@miksumia.com.
We acknowledge them within two business days.
- Fixes follow the
Atlassian Marketplace security bug fix policy:
critical within 10 days, high within 4 weeks, medium within 12 weeks,
low within 25 weeks.
- Affected customers are informed.
- Atlassian is informed through its Marketplace security process.
The full procedure is on the security page.
8. Logging
- Logs hold event names, technical identifiers, counters and error
codes.
- Production logs hold no customer content.
- Logs are kept by Atlassian Forge.
9. Data retention and deletion
What is kept, and for how long, is described in section 7 of the
privacy policy.
On uninstallation, the application first revokes the Google token. Atlassian
then deletes the stored data after 28 days.
10. Workstation
The founder's computer runs Microsoft Defender and the Windows firewall,
with automatic updates. Defender and the firewall were checked active on
5 October 2026. The screen locks automatically after 10 minutes of
inactivity and asks for the password to resume (checked on 6 October 2026).