Veridian NextGen

Privacy and security

Expand Plus for Confluence · last updated 7 September 2026

The short version

The app requests no permissions at all. It collects nothing, stores nothing and transmits nothing.

Data collected

None.

Data stored

None. The app declares no storage scope and has no database, no cache and no external service.

Data transmitted

None. No outbound network calls of any kind.

Sub-processors

None.

Permission scopes requested

Zero. The permissions block is absent from the app manifest. You can confirm this on the install screen: an app requesting no scopes shows no permission list.

How the app sees your page content

It does not fetch it. When Confluence renders a bodied macro, it hands the macro its own body as part of the render context. The app reads that context object, renders it, and the object is discarded when the page render ends. Nothing is copied, logged or kept.

Data residency

The app inherits your Confluence site's data residency. Because it stores nothing and transmits nothing, no data leaves that boundary.

Security patching

Security issues are patched within 10 business days of a confirmed report, in line with Atlassian Marketplace security requirements. Report to support@veridiannextgen.com with SECURITY in the subject line.

Incident notification

Because the app holds no customer data, there is no customer data to breach. Any vulnerability found in the app itself will be disclosed on this page within five business days of a fix being published.