Security policy
This page describes how Horizon Ventures E.I.R.L. builds, ships and supports its Atlassian Marketplace apps, and how to reach us about a security issue. Last updated 16 September 2026.
Where the apps run
All of our apps are built on Atlassian Forge and run inside Atlassian's own cloud infrastructure. We operate no servers, no databases and no log storage of our own, and there is no backend of ours for app data to travel to.
Page content is read in the customer's own Confluence site, in the context of the user who triggered the action, and the result is handed back to that user. Nothing is transmitted to Horizon Ventures.
Customer data
- We do not store end-user data, inside or outside Atlassian.
- We do not log end-user data.
- We do not share any data with third parties, because we hold none to share.
- Our apps declare no external egress: they call no hosts outside Atlassian at runtime.
Each app requests the smallest set of Atlassian scopes that lets it do its job, and every scope is listed with its justification on the app's Privacy and Security tab in the Marketplace.
Access control
Horizon Ventures is a one-person company. There are no employees, contractors or subprocessors with access to app code, to the Marketplace partner console or to the Atlassian developer console. Access to those consoles requires two-factor authentication, which Atlassian makes mandatory for Marketplace partners.
Development and release
App code is kept in a private repository. Releases are built and deployed through the Forge CLI to Atlassian's infrastructure, and customers receive updates through the Atlassian platform. We do not distribute binaries by any other channel.
Reporting a vulnerability
Write to support@horizonventures.app with the word SECURITY in the subject line. The message goes straight to the developer.
- We acknowledge a report within one working day.
- We fix confirmed vulnerabilities within the timeframes of the Atlassian Security Bug Fix Policy for Marketplace apps, by severity.
- We keep the reporter informed until the fix ships, and we credit reporters who want to be credited.
Please do not test against other customers' sites. If you need an instance to reproduce an issue on, ask us and we will provide one.
Incidents
If an incident affects customer sites, we notify the affected customers and Atlassian, describe what happened in plain language, and say what we changed so that it does not happen again. Given the architecture above, our realistic incident surface is the app code itself and access to the partner consoles.
Contact
Horizon Ventures E.I.R.L., registered in Peru, RUC 20612763888, Calca, Cusco.
Security and support: support@horizonventures.app.
See also our privacy policy and terms of use.