Community moderators have prevented the ability to post new comments.
This is a very real concern, especially in Jira and Confluence environments where thousands of issues, pages, comments, and attachments are added every day.
One thing we often overlook is that once sensitive data is stored, the exposure has already started. It may be visible to project members, searchable, included in exports/backups, or passed to connected systems before anyone notices it.
For this reason, we look at DLP as an ongoing process rather than a one-time cleanup:
This is the approach we've taken with the miniOrange DLP Sensitive Data Scanners for both Jira and Confluence:
The goal isn't just “find PII.” It's to shorten the time sensitive data remains exposed: Detect → Review → Remediate → Audit.
Curious how other teams are approaching this — do you run scheduled DLP scans, real-time detection, or a combination of both?
Hi @Emma Phillips !
I think it is probably the most difficult aspect to deal with the old data problem; although permissions and user awareness can help stop sensitive data from being added, they won't inform you about what is already concealed in the old Jira work items or comments.
With Jira Cloud, you can try the Security Scanner available in Issue History for Jira (Work Item History) app by SaaSJet. It checks Jira work items and their change history for sensitive data, including credentials, credit card numbers, SSNs, email addresses, phone numbers, IP addresses, and physical addresses.
The results include the findings, the work items where they were found, and the extent of the problem, enabling teams to swiftly determine what requires review or cleaning. Moreover, sensitive values can be masked, and access to the scanner can be restricted to admins or specific groups.
We also intend to include scheduled scanning, which will allow regular checks to be run automatically rather than having them started manually.
This relates to the Jira Cloud aspect of your question and can be particularly useful when you are looking for sensitive data that has been there unnoticed for a long time.
Community moderators have prevented the ability to post new comments.