DECISION GUIDE · REVIEWED AUGUST 2, 2026
Secret Sentinel Standard vs Advanced
Compare Secret Sentinel editions without hiding the key fact: core detection, redaction, escalation, exclusions, and ignore controls are included in both.
Short verdict
Choose Standard for the complete built-in protection workflow. Choose Advanced when administrators also need aggregate compliance visibility or organization-specific credential patterns.
Why this is not a “winner” page
Advanced does not unlock stronger built-in redaction or reserve supported credential types for a higher tier. The core safety control is the same in both editions.
Advanced adds two administration capabilities: an aggregate dashboard and custom patterns compiled by RE2JS. The dashboard stores integer counts, not finding records or secret values.
Side-by-side comparison
| Decision criterion | Standard | Advanced | Evidence |
|---|---|---|---|
| 50+ built-in credential types | Included. | Included. | Edition definition |
| In-place redaction | Included. | Included; identical behavior. | Product page |
| Jira escalation and severity controls | Included. | Included; identical behavior. | Edition definition |
| Project/space exclusions and ignored values | Included. | Included. | Product controls |
| Aggregate dashboard | Not included. | Counts by credential type, effective severity, and month. | Stored-data inventory |
| Custom credential patterns | Not included. | Admin-defined patterns compiled with the linear-time RE2JS engine. | Detection methodology |
| Best fit | Teams that need the complete built-in detection and response workflow. | Teams that need reporting visibility or proprietary internal token formats. | Edition definition |
Choose Standard when
- Built-in credential coverage meets the organization’s needs.
- The team does not require aggregate trend charts.
- No proprietary credential shape needs a custom rule.
Choose Advanced when
- Security or compliance needs aggregate counts by type, severity, and month.
- The organization issues internal tokens with a documented custom format.
- Administrators accept responsibility for testing organization-authored patterns.
Continue the evaluation
Evaluate with synthetic data before production
Inspect the public fixtures, review the architecture, then install on an Atlassian sandbox. Never use a live credential as a scanner test value.