Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

How to Protect Sensitive Data in Large Jira/Confluence Instances

Utkarsh Chandel
August 18, 2026

With so many Jira issues and Confluence pages created daily, strong data loss prevention (DLP) is essential to stop confidential data from slipping in unnoticed.

Do you run daily scans on new content, or rely on weekly/monthly compliance checks? Do you adjust schedules by project, space, or data sensitivity?

How do you decide what requires frequent monitoring to reduce data leakage risk? I’m also interested in how teams balance scan frequency with performance impact on large instances. Some use continuous monitoring for high‑risk areas, while others rely on scheduled DLP scans for lower‑sensitivity spaces.

Would love to hear what data protection strategies have worked best for others managing information security in Jira and Confluence. 

2 answers

2 accepted

2 votes
Answer accepted
ben friedman
Contributor
August 19, 2026

Hi @Utkarsh Chandel while reviews have their place, i see that is a post fact check. I would prefere gating access as the first steps. 

User permissions in both jira and confluence, especially around delete, should be checked and made up to a standard. i woulld set delete permissions with only several users in the organization to constrain that with a bottle neck.

You cant guard against personal pages that user create in their blogs from being deleted, but as a practice, important documents should not be personal documents.

Another option is using a backup, in case something was lost unintentionally.  there are several options to consider here, from 3rd party apps, atlassian's own backup/restore solution, and doing manual backsups to a sandbox from which you can restore data.

2 votes
Answer accepted
Adam Fox
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
August 18, 2026

I think a mix of both works well. High-risk projects and spaces should be monitored more frequently, while lower-risk areas can be checked on a regular schedule. That helps catch sensitive data early without putting too much load on larger Jira and Confluence instances.

It also makes sense to adjust the scan frequency based on the type of data and how often that area changes.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
STANDARD
TAGS
AUG Leaders

Atlassian Community Events