Secret Sentinel Trust Center

This page is the technical source of truth for evaluating Secret Sentinel for Jira and Confluence. It distinguishes properties verified in the application manifests and source architecture from guarantees supplied by Atlassian Forge. Last reviewed: 2 August 2026.

Both Marketplace listings carry the Runs on Atlassian badge. Atlassian applies this badge to apps whose compute and storage remain on Atlassian systems, whose supported data-residency behavior matches the host product, and whose customer data does not leave through developer- controlled analytics or logs. It is a meaningful architecture signal, not a certification or a claim that Atlassian assumes every application-security responsibility. See Atlassian’s badge criteria and shared-responsibility explanation.

Secret Sentinel data-flow diagram: Jira issues and comments or Confluence pages, blog posts, and comments enter an Atlassian Forge function; detection, severity classification, redaction, Forge key-value settings, aggregate statistics, and optional Jira incident creation remain inside the Atlassian boundary; no remote backend or external egress is declared.

Data flow, in exact terms

When supported Jira or Confluence content is created or updated, a Forge event invokes Secret Sentinel. The app reads the supported text, detects credential patterns, classifies findings, redacts matched spans in place, and can create a Jira remediation item when configured. Detection does not call a Simplify server or a third-party scanning API.

The production manifests declare no remotes and no external egress domains. The code uses Forge-authenticated Atlassian APIs and Forge KVS; a source review found no application logging calls. Atlassian notes that all Forge runtime Internet requests pass through an outbound proxy that enforces manifest egress permissions. Read the platform detail in Security for Forge apps.

What is stored

Secret Sentinel does not maintain a second copy of Jira issues or Confluence documents. Forge KVS stores configuration, including enabled state, escalation settings, exclusions, severity overrides, custom detection rules, and ignored-value labels. An ignored raw value is converted to a SHA-256 hash before persistence; the original value is not stored in settings.

Advanced edition dashboard data is three maps of integers: byType (for example, github_token: 4), bySeverity (for example, high: 4), and byMonth (for example, 2026-08: 4). A successful redaction increments the relevant counters. The record contains no secret value or matched hash, issue key, page ID, document excerpt, timestamp, or per-detection entry. Concurrent events can occasionally lose an increment because Forge KVS has no atomic increment primitive, so these values are trend indicators rather than billing or SLA evidence.

The only Secret Sentinel records to which Forge’s uninstall retention applies are app settings, ignored-value {label, SHA-256 hash} pairs, and those aggregate integer counters—not detected secrets, findings, or copies of Jira and Confluence content. Forge encrypts this hosted storage on disk, scopes it per app installation, and retains it for 28 days after uninstall. Recovery requires customer consent and a request within 21 days. Those lifecycle rules are Atlassian controls, documented in the official Forge storage reference.

Requested permissions and why

Scope Jira app Confluence app Purpose
read:jira-work Yes Yes Read supported Jira content and configuration targets
write:jira-work Yes Yes Redact Jira content and optionally create remediation items
read:jira-user Yes Yes Resolve configured assignees
read:page:confluence / read:comment:confluence No Yes Scan pages, blog posts, and comments
write:page:confluence / write:comment:confluence No Yes Replace detected spans with redaction markers
read:space:confluence No Yes Resolve configured space exclusions
storage:app Yes Yes Store installation settings and aggregate dashboard counts

The two apps are independent. Confluence-to-Jira escalation requires both apps on the same site; ordinary Confluence scanning does not.

Explicit limitations

Secret Sentinel scans Jira issue text and comments, and Confluence page, blog-post, and comment content. It does not scan attachments, the contents behind external links, source-code repositories, chat systems, or other products. Pattern detection is best-effort: no detector can guarantee every unknown or malformed credential will be found. Redaction does not revoke a credential; the owner must rotate it after exposure.

Custom regular expressions use RE2JS, a linear-time engine designed to prevent catastrophic backtracking. Detection behavior, testable examples, and false-positive boundaries are explained in the open methodology.

Operational assurance

  • Hosting: Atlassian Forge compute and hosted storage; no vendor-operated runtime or database.
  • Tenant storage: Forge KVS is automatically scoped per installation. Application state is not kept in mutable module-level caches.
  • Vendor subprocessors for app data: none. Atlassian supplies the underlying Forge platform.
  • Certifications: Simplify does not claim a separate SOC 2 or ISO 27001 certification for Secret Sentinel. Runs on Atlassian is an architecture badge, not either certification.
  • Security reports: use the vulnerability disclosure policy. Do not include a live credential or customer content in an initial report.
  • Privacy: see the product privacy policy.

Evidence and review material

Use the security review pack for a concise procurement handoff, the admin approval kit for an installation request, and the technical documentation for safe test values. Questions not answered here can be sent to [email protected].