Secret Sentinel Trust Center
This page is the technical source of truth for evaluating Secret Sentinel for Jira and Confluence. It distinguishes properties verified in the application manifests and source architecture from guarantees supplied by Atlassian Forge. Last reviewed: 2 August 2026.
- Install for Jira
- Install for Confluence
- Download the security review pack
- Copy an admin approval request
- Explore safe, precomputed scanner scenarios
- Review the privacy-preserving regression benchmark
Both Marketplace listings carry the Runs on Atlassian badge. Atlassian applies this badge to apps whose compute and storage remain on Atlassian systems, whose supported data-residency behavior matches the host product, and whose customer data does not leave through developer- controlled analytics or logs. It is a meaningful architecture signal, not a certification or a claim that Atlassian assumes every application-security responsibility. See Atlassian’s badge criteria and shared-responsibility explanation.
Data flow, in exact terms
When supported Jira or Confluence content is created or updated, a Forge event invokes Secret Sentinel. The app reads the supported text, detects credential patterns, classifies findings, redacts matched spans in place, and can create a Jira remediation item when configured. Detection does not call a Simplify server or a third-party scanning API.
The production manifests declare no remotes and no external egress domains. The code uses Forge-authenticated Atlassian APIs and Forge KVS; a source review found no application logging calls. Atlassian notes that all Forge runtime Internet requests pass through an outbound proxy that enforces manifest egress permissions. Read the platform detail in Security for Forge apps.
What is stored
Secret Sentinel does not maintain a second copy of Jira issues or Confluence documents. Forge KVS stores configuration, including enabled state, escalation settings, exclusions, severity overrides, custom detection rules, and ignored-value labels. An ignored raw value is converted to a SHA-256 hash before persistence; the original value is not stored in settings.
Advanced edition dashboard data is three maps of integers: byType (for example,
github_token: 4), bySeverity (for example, high: 4), and byMonth (for example,
2026-08: 4). A successful redaction increments the relevant counters. The record contains no
secret value or matched hash, issue key, page ID, document excerpt, timestamp, or per-detection
entry. Concurrent events can occasionally lose an increment because Forge KVS has no atomic
increment primitive, so these values are trend indicators rather than billing or SLA evidence.
The only Secret Sentinel records to which Forge’s uninstall retention applies are app settings,
ignored-value {label, SHA-256 hash} pairs, and those aggregate integer counters—not detected
secrets, findings, or copies of Jira and Confluence content. Forge encrypts this hosted storage on
disk, scopes it per app installation, and retains it for 28 days after uninstall. Recovery requires
customer consent and a request within 21 days. Those lifecycle rules are Atlassian controls,
documented in the official
Forge storage reference.
Requested permissions and why
| Scope | Jira app | Confluence app | Purpose |
|---|---|---|---|
read:jira-work |
Yes | Yes | Read supported Jira content and configuration targets |
write:jira-work |
Yes | Yes | Redact Jira content and optionally create remediation items |
read:jira-user |
Yes | Yes | Resolve configured assignees |
read:page:confluence / read:comment:confluence |
No | Yes | Scan pages, blog posts, and comments |
write:page:confluence / write:comment:confluence |
No | Yes | Replace detected spans with redaction markers |
read:space:confluence |
No | Yes | Resolve configured space exclusions |
storage:app |
Yes | Yes | Store installation settings and aggregate dashboard counts |
The two apps are independent. Confluence-to-Jira escalation requires both apps on the same site; ordinary Confluence scanning does not.
Explicit limitations
Secret Sentinel scans Jira issue text and comments, and Confluence page, blog-post, and comment content. It does not scan attachments, the contents behind external links, source-code repositories, chat systems, or other products. Pattern detection is best-effort: no detector can guarantee every unknown or malformed credential will be found. Redaction does not revoke a credential; the owner must rotate it after exposure.
Custom regular expressions use RE2JS, a linear-time engine designed to prevent catastrophic backtracking. Detection behavior, testable examples, and false-positive boundaries are explained in the open methodology.
Operational assurance
- Hosting: Atlassian Forge compute and hosted storage; no vendor-operated runtime or database.
- Tenant storage: Forge KVS is automatically scoped per installation. Application state is not kept in mutable module-level caches.
- Vendor subprocessors for app data: none. Atlassian supplies the underlying Forge platform.
- Certifications: Simplify does not claim a separate SOC 2 or ISO 27001 certification for Secret Sentinel. Runs on Atlassian is an architecture badge, not either certification.
- Security reports: use the vulnerability disclosure policy. Do not include a live credential or customer content in an initial report.
- Privacy: see the product privacy policy.
Evidence and review material
Use the security review pack for a concise procurement handoff, the admin approval kit for an installation request, and the technical documentation for safe test values. Questions not answered here can be sent to [email protected].