Link-a-Link

Partner Security Policy

How Agilva Solutions secures Link-a-Link, handles vulnerabilities, and responds to security incidents.

Atlassian Marketplace Partner

This policy is published in accordance with Atlassian's Marketplace Partner Security requirements and covers the security controls, vulnerability management processes, and incident response procedures for the Link-a-Link plugin.

Architecture overview

Link-a-Link is built exclusively on the Atlassian Forge platform โ€” Atlassian's serverless, managed runtime for Confluence and Jira apps. The plugin does not operate any independent servers, virtual machines, or databases. All code executes within Atlassian's Forge sandbox with strict tenant isolation enforced at the platform level.

URL mapping data is stored in AWS S3 (eu-west-1, Ireland) with AES-256 encryption at rest and TLS 1.2+ in transit. IntellinQ configurations and plugin settings are stored in Forge Storage, managed entirely by Atlassian.

Key security facts

AreaSummary
HostingAtlassian Forge (serverless, Atlassian-managed)
Data storageAWS S3 (eu-west-1) + Atlassian Forge Storage
Encryption at restAES-256 (SSE-S3)
Encryption in transitTLS 1.2+
Personal data collectedNone โ€” no names, emails, account IDs, or search queries
Tenant isolationApplication-layer + Forge platform-layer + S3 IAM
Security contactprivacy@agilva.com

Version 1.0 ยท Effective date: 08 April 2026