Skip to:

Marketplace

Secret Sentinel - Password Leak Scanner for Confluence

works with Confluence Cloud

OVERALL RATINGS

INSTALLS

50

SUPPORT

  • Partner Supported

TRUST SIGNALS

Requires

CONFLUENCE

Works with

JIRA

Showing details for Cloud

Key highlights of the appDetect and redact 50+ leaked credential types in Confluence — with automatic Jira incident escalation

watch Secret Sentinel - Password Leak Scanner for Confluence video

Detect and redact 50+ credential types

Scans Confluence pages and comments for AWS/GCP keys, GitHub and Stripe tokens, database connection strings, SSH/PEM private keys, JWTs, and more — then redacts each one in place, formatting preserved.

Escalate high-risk leaks straight to Jira

A real, exploitable secret can auto-open a tracked Jira incident with project, issue type, priority, and assignee already set (requires Secret Sentinel for Jira, same site) — not just a dashboard entry nobody checks.

Tune detection to your organization

Override severity and escalation per credential type or space, mark known-safe placeholder values as permanently ignored, and add your own regex patterns with the Advanced edition's ReDoS-safe custom rule engine.

Supporting media

Editions
New

This app offers two different editions - Standard and Advanced. You can start a free trial of either edition, and change your edition anytime during or after the trial.

Standard

Onboard your team and scale fast

Includes:

  • Automatic secret detection & redaction

  • Broad secret type coverage

  • Jira incident escalation

  • Severity & escalation rules

  • Per-value allowlist

Advanced

Unlock the full range of app features

Everything from Standard, plus:

  • Custom regex detection rules

  • Compliance dashboard

More details

Secret Sentinel scans Confluence content for 50+ types of leaked credentials — AWS and GCP keys, GitHub and Stripe tokens, DB connection strings, SSH/PEM private keys, JWTs, and more — built on the open-source secretlint engine, not a closed pattern list. Every finding is classified by real exploitability, not keyword matching, so you see fewer, more meaningful alerts. Secrets are redacted in place with formatting preserved.

High-risk leaks can auto-open a tracked Jira incident (requires Secret Sentinel for Jira, same site). Severity, escalation, and exclusions are configurable per credential type — every override is auditable.

Built entirely on Atlassian Forge — no external servers, no environment variables, nothing leaves your instance. Advanced edition adds a compliance dashboard and custom, ReDoS-safe regex patterns.

Verify before installing: Trust Center — data flow, storage, permissions, benchmark, and methodology.

Resources

  • App documentation

    Comprehensive set of documentation from the partner on how this app works

Privacy and Security

Privacy policy

Atlassian's privacy policy is not applicable to the use of this app. Please refer to the privacy policy provided by this app's partner.

Partner privacy policy

Security program

This app is not part of the Marketplace Bug Bounty program.

Integration permissions

Secret Sentinel - Password Leak Scanner for Confluence integrates with your Atlassian app

Version information

Version 3.0.0for Confluence Cloud

Release date
Aug 4th 2026
Summary
Required scopes and editions enabled status changed
Details

Required scopes changed:

  • Added: read:space:confluence
Payment model
Paid via Atlassian
License type
Commercial

Learn and explore

  • What’s Marketplace
  • App installation
  • About Atlassian
  • Atlassian resources
  • Search and ranking
  • Atlassian events
  • Atlassian foundation

Follow