OVERALL RATINGS
INSTALLS
1
SUPPORT
- Partner Supported
TRUST SIGNALS
Key highlights of the appField-level security for Jira: protected values live outside Jira's data layer and render only for the people you authorize
More details
Secure Fields is built for regulated teams (healthcare, finance, legal, etc) that need specific values kept out of Jira's data layer. Values entered through the Secure Text field are stored in Forge storage on Atlassian's platform and shown only to the Jira groups and project roles you authorize. The Jira field holds only a [secured] marker, so values never appear in the REST API, JQL search, or CSV export. Access is checked server-side and denied by default; reveals, edits, and permission changes are logged (metadata only, never the value).
The app runs entirely on Atlassian's infrastructure with no external data egress and follows your site's data residency. It is designed to support HIPAA, SOC 2, GDPR, and ISO 27001 compliance programs as a technical access control, not a certification. By design, secured values are not JQL-searchable or reportable and are excluded from Jira backups.
Resources
App documentation
Comprehensive set of documentation from the partner on how this app works
Privacy and Security
Privacy and security questionnaire has been filled by the partner
Privacy policy
Atlassian's privacy policy is not applicable to the use of this app. Please refer to the privacy policy provided by this app's partner.
Partner privacy policySecurity program
This app is not part of the Marketplace Bug Bounty program.
Integration permissions
Secure Fields for Jira integrates with your Atlassian app
Version information
Version 2.1.0•for Jira Cloud
- Release date
- Jul 21st 2026
- Summary
- Initial release: Secure Text field with group/role access rules and audit log
- Details
Initial public release of Secure Fields.
- Secure Text custom field: values are stored in Forge storage, never in the Jira field, so they never appear in REST, JQL, or CSV export (only a [secured] marker).
- Per-field view/edit rules by Jira group and project role, enforced server-side. Deny by default; unauthorized users see a masked placeholder.
- Admin page to set rules, with Preview access and a confirmation step before saving.
- Access audit log for reveals, edits, and permission changes (metadata only, never the value), queryable by time, issue, field, user, or action.
- Runs on Atlassian: no external egress; data stays on Atlassian's platform, encrypted at rest and in transit (TLS 1.2+).
By design: secured values are not JQL-searchable or reportable, and are excluded from Jira backups/exports. Set values on the issue view after creating the issue.
- Payment model
- Paid via Atlassian
- License type
- Commercial