← Sealwell
DocumentationPrivacyEULASupport

Sealwell documentation

Source for the public knowledge base (Sealwell Docs, SWDOCS) and the listing's Documentation URL.

Getting started

  1. Edit a page, type /Secure section and insert the macro. Publish the page if it is new.
  2. On the published page, click Set up in the macro.
  3. Choose a mode:
    • Restricted section: text that chosen people read inline with the page. Supports # headings, - and 1. lists, **bold**, *italic*, `code`, fenced code blocks, > quotes and [links](https://...).
    • Secrets: named values (passwords, keys, codes) that stay masked until revealed.
  4. Who can see it: add people, groups, or "everyone who can view the page". For each person or group you can set the date their access ends.
  5. Owners: you are an owner. Add a group so the section never loses its owner when someone leaves. Owners can always see, edit and delete the section.
  6. Optional: an expiry date (after it, only owners can open the section) and Hide it completely (people without access see nothing instead of a placeholder).
  7. Save. The page itself still contains only the macro.

Who sees what

Every time the section loads, Sealwell checks, on the server:

  1. Can this person view the page? If not, they see nothing.
  2. Are they an owner (directly or through a group)? Owners see everything.
  3. Has the section expired? Then only owners can open it.
  4. Are they in the audience, and has their access not ended? Readers see the content; for secrets, they see the names and reveal values one at a time.
  5. Otherwise: a placeholder with the title and owners to ask, or nothing if the owner chose "Hide it completely".

Anonymous visitors and guests without a Confluence account never see protected content.

Secrets

Click Reveal to show one value. It hides again after 30 seconds (your admin can change this) or when you click Hide. Each reveal is checked again on the server and logged.

Activity

Owners click Activity on a section to see the last 50 events: created, edited (with what changed), viewed, revealed, denied, copied. Views and denials are logged at most once an hour per person; every reveal is logged. Secret names and values are never logged.

Copying pages and templates

Copying a page copies the macro but never the protected content: the copy shows an empty section. Owners of the original see Copy "..." from the original page and can bring the content, owners and audience over in one click (logged on both sections). Others set it up from scratch.

For Confluence admins

Confluence settings > Secure sections:

  • Sections: every section with its page, owners and audience size. Content is never shown. Set owners recovers a section whose owners left. Delete removes it. Find sections of deleted pages lists sections whose page was deleted from the trash (archived and trashed pages are kept, so a restore brings them back) and deletes them on confirmation.
  • Audit log: the whole site, filter by section, export up to 5,000 rows as CSV.
  • Settings: limit who can create sections to chosen groups; require an owner group; how long revealed secrets stay visible; audit retention (90 days, 180 days, 1 year, forever).
  • Encryption: the current key version and Rotate the key, which creates a new site key, re-encrypts every section and deletes the old key.

To read a section's content, an admin must be an owner and able to view the page. Both are logged.

Security model

  • Content is encrypted with AES-256-GCM using a random key for your site. The key is kept in Forge secret storage; the encrypted content in Forge app storage. Both are hosted by Atlassian in your data residency region. Nothing is sent outside Atlassian.
  • The page holds only the macro, so page history, PDF and Word exports, Confluence search and the REST API never contain protected text.
  • Sealwell is not end-to-end or zero-knowledge encryption. The app decrypts on Atlassian's Forge platform for people who pass its permission check. That is what lets it work with SSO and groups, without shared passwords.

When the subscription ends

Readers see "The subscription or trial has ended". Owners can still open and delete their sections. No sections can be created or edited until it is renewed.

Uninstalling

Uninstalling deletes the app's storage, including the encryption keys, under Atlassian's Forge data deletion process. Protected content cannot be recovered afterwards by anyone. Owners should open each section and copy what they need before an admin uninstalls.

Limits

  • Protected text is not searchable in Confluence (by design).
  • A new page must be published once before a section can be set up.
  • Up to 50 secrets per section, 50,000 characters of section text, 100 people and groups per list.