Many enterprise migration plans focus on the visible logistics: user mapping, app assessment, data volume, testing, cutover planning, and downtime. Those activities are essential, but I’m also interested in how teams are handling the content-security side of the migration.
Before moving from Jira and Confluence Data Center to Cloud, are you reviewing the actual content payload- not just instance size and configuration?
Areas I’m especially interested in include:
- API tokens, passwords, and internal production URLs stored in issue descriptions, comments, or documentation.
- Customer or employee PII in Jira, Confluence pages, attachments, and page histories.
- Sensitive information in text files, spreadsheets, CSV files, and other attachments.
- Old projects, inactive users, obsolete pages, and unnecessary historical content.
- Retention, deletion, redaction, and audit requirements before migration.
- How teams validate that sensitive information has been removed without damaging useful project history.
My current view is that migration readiness should include two distinct activities:
- Migration assessment: understanding the size, structure, applications, users, cost reduction, and technical health of the Data Center environment.
- Data sanitization: reviewing content and attachments for sensitive information, then applying an approved remediation, encrypting the data to prevent leaks, and an audit process before cutover.
I’m not suggesting that every organization needs the same process or tool. The right approach will depend on regulatory obligations, data-retention policies, industry requirements, and the migration scope.
For those who have completed or are planning a Data Center-to-Cloud migration:
- Did you perform a dedicated sensitive-data discovery exercise?
- Which Jira and Confluence content types did you include?
- How did you handle attachments and historical versions?
- Did you redact, delete, archive, or exclude content?
- How did you document approvals and evidence for security or audit teams?
- What did you wish you had added to the migration plan earlier?
Disclosure: I work for miniOrange, which develops a Data Center solution for sensitive-data discovery and remediation and cost-saving migration. I’m sharing this to compare migration practices and learn from other Atlassian administrators; I’m not requesting product support or promoting a specific migration approach.