Secret Sentinel Admin Approval Kit

Atlassian users can request Marketplace apps from their site administrator. A useful request does more than say “please install this”: it tells the reviewer what the app reads, where processing happens, how to validate it, and how to remove it.

Jira request — copy and send

Subject: Request to evaluate Secret Sentinel for Jira

Please evaluate Secret Sentinel – Password & Leak Scanner for Jira:
https://marketplace.atlassian.com/apps/1051006300/

Business need: credentials can be pasted into issue summaries, descriptions, and comments outside
our repository controls. The app detects supported credential patterns, redacts matched spans, and
can create a Jira remediation item for high-risk findings.

Architecture: the listing has the Runs on Atlassian badge. Processing and app storage use Atlassian
Forge; the app declares no remote backend or external egress. Requested Jira scopes are used to
read supported content, redact it, create configured remediation items, resolve assignees, and keep
installation settings and aggregate counts in Forge KVS.

Proposed evaluation: install first on a sandbox, use only the vendor's synthetic test values,
verify redaction and expected false-positive controls, review incident routing, and uninstall if
acceptance criteria are not met.

Evidence: https://simplify-software.org/trust
Security policy: https://simplify-software.org/security

Download this Jira request as text.

Confluence request — copy and send

Subject: Request to evaluate Secret Sentinel for Confluence

Please evaluate Secret Sentinel – Password & Leak Scanner for Confluence:
https://marketplace.atlassian.com/apps/2527876384/

Business need: runbook pages, blog posts, and comments can contain credentials that repository
scanners never see. The app detects supported credential patterns and redacts matched spans. Jira
incident creation is optional and requires the companion Jira app on the same site.

Architecture: the listing has the Runs on Atlassian badge. Processing and app storage use Atlassian
Forge; the app declares no remote backend or external egress. Confluence scopes cover reading and
redacting supported content and resolving space exclusions; Jira scopes support optional incident
routing; Forge KVS stores settings and aggregate counts.

Proposed evaluation: install first on a sandbox, use only the vendor's synthetic test values,
verify page and comment redaction, review exclusions and incident routing, and uninstall if
acceptance criteria are not met.

Evidence: https://simplify-software.org/trust
Security policy: https://simplify-software.org/security

Download this Confluence request as text.

Acceptance criteria for a sandbox trial

Use synthetic values from the documentation, never a live token. Confirm the supported content types, exact redaction boundary, severity, duplicate behavior, configured exclusions, and optional incident fields. Then record who owns credential rotation: deleting or masking a leaked value does not revoke it.

The full scope and retention explanation is in the Trust Center, and the compact reviewer handoff is the security review pack.