# Security and privacy Most security questions about Capable have the same root answer: these are Atlassian Forge apps, and Forge constrains what an app can do in ways Atlassian enforces rather than we promise. This section is the orientation. The precise answers for a given product live in that product's own security section. --- ## In this section [How Capable apps are builtEvery Capable app for Confluence runs on Atlassian Forge, which decides most of the answers a security review asks for.](https://help.gocapable.com/trust/how-capable-apps-are-built.html)[Reporting a security issueHow to report a suspected vulnerability, and what we do with it.](https://help.gocapable.com/trust/reporting-a-security-issue.html)[Where our services runWhich parts of Capable run where, and how to remove the parts that leave your tenant.](https://help.gocapable.com/trust/where-our-services-run.html) --- ## Related [LegalTerms, privacy and trademarks.](https://help.gocapable.com/trust/legal.html) [Service incidentsWhen something went wrong.](https://help.gocapable.com/trust/service-incidents.html) --- _The platform answers most of it._