SAFE PRODUCT WALKTHROUGH

See the scanner's behavior without pasting a secret

Choose a verified scenario from Secret Sentinel's automated test suite. Every input below is synthetic and precomputed. This page runs no detection engine, accepts no user content, and sends no credential to Simplify or a third party.

01

GitHub token in a Jira comment

Verified against the Jira ADF tree-walking redactor.

Synthetic input

leaked: ghp_a1B2c3D4e5F6g7H8i9J0k1L2m3N4o5P6q7R8 end

Expected Jira content

leaked: [REDACTED by Secret Sentinel:
github_token, ghp_****q7R8] end
Type
github_token
Severity
High
Content model
Jira ADF text node
Assertion
Surrounding text remains unchanged
What this scenario proves—and what it does not

The fixture verifies classification, masking, and replacement inside a Jira ADF text node. It does not claim attachment scanning, credential validity checking, or automatic revocation. A real detected credential must still be rotated.

02

AWS identifier and secret in Confluence

Verified against the Confluence storage-format HTML redactor.

Synthetic input

aws_access_key_id=AKIAABCDEFGHIJKLMNOP
aws_secret_access_key=abcdEFGHijkl1234abcdEFGHijkl1234abcdEFGH

Expected classification

aws_access_key_id       → Medium
aws_secret_access_key   → High
both matched spans      → Redacted

The access-key ID is an identifier and is not independently exploitable, so the test expects Medium. The paired secret is High. This distinction prevents a bare identifier from being represented as equivalent to an usable credential.

Why the familiar AWS documentation key is not used as the positive case

AWS's well-known AKIAIOSFODNN7EXAMPLE documentation identifier is explicitly expected to produce no finding. The positive fixture above is constructed for the test suite and was not issued by AWS.

04

A placeholder must remain untouched

A useful scanner needs negative tests, not only impressive positive examples.

Input

token=changeme

Expected result

Findings: 0
Content mutation: none
Jira incident: none

This fixture exercises placeholder filtering for a generic assignment. It does not mean every string containing “example” is globally ignored: provider rules have their own documented behavior, and administrators can maintain installation-specific ignored values.

05

Already-redacted content stays unchanged

Repeated content events must converge instead of nesting redaction markers.

Input from a previous scan

[REDACTED by Secret Sentinel:
aws_access_key_id, AKIA****MNOP]

Expected second scan

Output: byte-for-byte unchanged
New findings: 0
Nested marker: none

How these demonstrations were selected

The results are transcribed from automated fixtures and unit-level behavior in the private Secret Sentinel codebase, reviewed on 2 August 2026. The public page contains inputs and expected outputs only—not production patterns or executable detection logic. For the rule composition, severity model, and known limitations, read theopen methodology andTrust Center.

A walkthrough can establish expected behavior, but only an installed sandbox evaluation can exercise Atlassian events, permissions, configuration, and incident routing together.

Run the real acceptance test in your Atlassian sandbox

Install the relevant app, copy the same synthetic fixtures, and compare the result with this page. Do not use a live or previously active credential.