Skip to:

Marketplace

FileWarden Attachment Governance for Jira

works with Jira Cloud

OVERALL RATINGS

SUPPORT

  • Partner Supported

TRUST SIGNALS

Showing details for Cloud

Key highlights of the appBlock risky Jira attachments by type, name, size, or count and scan for secrets and PII; block executables on Confluence

hero

Block disallowed files on every upload path

Every Jira upload path is covered: comments, descriptions, forms, and fields. A blocked file - wrong type, oversized, duplicate, or over the limit - is removed with a policy comment. Confluence blocks executables.

Scan inside documents for secrets and PII

Go beyond file type. FileWarden scans text, PDF, and Office files for AWS keys, GitHub and Slack tokens, JWTs, credit cards, and US SSNs, with zero egress (Pro). The value is never shown or logged.

Reversible quarantine and an exportable audit log

With quarantine on (Pro), a removal copies the file to a holding issue first and an admin can restore it within the retention window. Every action is logged newest-first with file, reason, and source (CSV, Pro).

Supporting media

More details

Stop risky and non-compliant attachments piling up in Jira. Jira Cloud has no pre-upload hook, so a .exe, an oversized export, or a stray secret.env can land through a comment, a description, a form, a field, or a service desk request - and stay there. FileWarden watches every upload path, auto-removes what breaks your policy, posts a comment naming the rule, and keeps an append-only audit trail.

Allow or block by extension, MIME type, filename pattern, size, count, or duplicate. Start from a template (block executables, secrets, HIPAA, PCI-DSS, GDPR, office-only) and tune it. Monitor mode dry-runs a policy before you enforce it; a grace period and bot exemptions make rollout safe.

Pro adds a zero-egress scan inside text, PDF and Office files for AWS keys, GitHub and Slack tokens, JWTs, credit cards and US SSNs, plus per-project and per-group rules, reversible quarantine, and a CSV audit log. Confluence blocks executables.

Runs 100% on Atlassian: no external servers, no egress.

Resources

  • App documentation

    Comprehensive set of documentation from the partner on how this app works

Privacy and Security

Privacy policy

Atlassian's privacy policy is not applicable to the use of this app. Please refer to the privacy policy provided by this app's partner.

Partner privacy policy

Security program

This app is not part of the Marketplace Bug Bounty program.

Integration permissions

FileWarden Attachment Governance for Jira integrates with your Atlassian app

Version information

Version 2.2.0for Jira Cloud

Release date
Jul 22nd 2026
Summary
Correctness fixes across the document scan, policy matching, and storage.
Details
A reliability release. No new features, no new permissions, nothing to reconfigure. - Document scan: text hidden behind an image layer, a ZIP64 archive, or the word "stream" in a title could leave a file unscanned. Headers, footers, footnotes and speaker notes are read now. - Policy matching: a trailing invisible character, a MIME parameter such as "; charset=utf-8", or an attachment id compared as text could match the wrong rule. Keep-the-oldest now really keeps the oldest. - Signature checking no longer calls a CSV a Windows executable on two leading letters. - The count limit and duplicate blocking no longer remove a unique file along with its duplicates. - The grace period, quarantine expiry and the blocked-file count relied on an index built only during a major upgrade, so on installs that took the code as a minor update they never ran. The migration is resumable now and also runs from the hourly sweep. - A storage write that partly failed was reported as successful.
Payment model
Paid via Atlassian
License type
Commercial

Learn and explore

  • What’s Marketplace
  • App installation
  • About Atlassian
  • Atlassian resources
  • Search and ranking
  • Atlassian events
  • Atlassian foundation

Follow