FileWarden
Attachment governance for Jira
Block risky or non-compliant attachments and catch leaked secrets and PII across every Jira upload path - with reversible quarantine and a full audit trail.
- Runs 100% on Atlassian
- No external egress
- Full audit trail

Govern every attachment, automatically.
Govern every attachment on every upload path
Comments, descriptions, forms, custom fields, and Jira Service Management requests are all covered. The moment a violation lands, FileWarden removes it - or quarantines it on Pro - and posts a clear comment explaining which policy it broke - no manual cleanup, no gaps.
Catch leaked secrets and PII inside documents
On Pro, a zero-egress content scan reads text files and extracts text from PDF, Word, Excel, and PowerPoint documents, looking for AWS keys, private keys, GitHub, Slack and Google tokens, JWTs, credit cards, US SSNs, and IBANs. The matched value is never shown or logged - FileWarden acts as a DLP layer without anything leaving Atlassian.
Exportable audit log and per-issue history
On Pro, review every action newest-first with the file, reason, and detection source, and export to CSV for auditors. A read-only panel on each issue shows what FileWarden did to its attachments, free.
Stop risky and non-compliant attachments from piling up in Jira. Jira Cloud has no pre-upload hook, so a .exe, an oversized export, or a stray secret.env can land through a comment, a description, a form, a custom field, or a service desk request - and stay there. FileWarden watches every upload path and auto-removes anything that breaks your policy - or quarantines it on Pro - posts a human-readable comment so people learn the rule, and keeps an append-only audit trail. It acts as a Jira DLP layer for attachment security - governing files by type, name, size, count, and duplicates, and scanning text, PDF, and Office files for leaked secrets and PII - with no antivirus engine and no external service.
Templates or your own rule
Start from a compliance template - block executables, block secrets, HIPAA, PCI-DSS, GDPR, or office-only - or allowlist and blocklist by extension, MIME type, filename, or size. Globally, or per project on Pro. Templates are a starting point you can tune.
Secret and PII content scan
On Pro, inside text files and inside PDF, Word, Excel, and PowerPoint documents, FileWarden looks for AWS keys, private keys, GitHub, Slack and Google tokens, JWTs, credit cards, US SSNs, and IBANs. The scan runs on Atlassian with zero egress and never shows or logs the matched value. There is no antivirus engine and no OCR - an image-only or encrypted document is treated as unreadable, never as a match.
Safe to roll out
Monitor mode logs what would be removed without deleting, a grace period gives uploaders time to fix a violation, and trusted bot and CI accounts can be exempted. On Pro, run a one-time scan of existing attachments to clean up what predates install.
Reversible remediation and audits
Quarantine instead of delete on Pro, then restore if a block was wrong. Every action is logged newest-first; on Pro the full audit log exports to CSV and a daily compliance digest lands on the admin page. The read-only per-issue panel is free.
Duplicates, counts, and transitions
Cap attachments per issue and block a file that is already there - by filename, or by byte-identical content hashed on Atlassian. A workflow validator can also stop a transition while a disallowed file is still attached, and it fails open so it never wedges a workflow.
Ask Rovo what happened
On Pro, the FileWarden Compliance agent reports what was removed, quarantined, or flagged over a window and can author a per-project block rule from the conversation. It is admin-only, re-verified server-side on every action.
Notifies inside Jira
When something is blocked, FileWarden posts to a tracking issue with an @mention and can raise a permission alert - no Slack or email needed, nothing leaves Atlassian.
Runs 100% on Atlassian
No external servers, no data egress, data residency honored - eligible for the Runs on Atlassian badge. The content scan runs on-platform too.
Everything it takes to keep attachments clean.
Block on Every Upload Path
Comments, descriptions, forms, custom fields, and Jira Service Management requests are all covered. When a violation lands, FileWarden removes it - or quarantines it on Pro - and posts a comment naming the policy it broke - no manual cleanup, no gaps.
Restrict File Types
Match by extension, MIME type, filename glob, or maximum size, as an allowlist or a blocklist. Set one global policy, or per-project rules on Pro.
Secret and PII Content Scan
On Pro, a zero-egress scan reads inside text, PDF, Word, Excel, and PowerPoint files for leaked secrets and PII - AWS keys, private keys, GitHub, Slack and Google tokens, JWTs, credit cards, US SSNs, and IBANs. The matched value is never shown or logged.
Compliance Policy Templates
Apply a sensible policy in one click: block executables, block secrets, or a HIPAA, PCI-DSS, GDPR, or office-only posture. Templates are a starting point you can tune.
Quarantine and Restore
On Pro, remove violations reversibly: quarantine an attachment instead of deleting it, then restore it if the block was wrong.
Monitor Mode and Grace Period
Dry-run a policy: Monitor mode logs what would be removed without deleting anything, and a grace period gives uploaders time to fix a violation before enforcement kicks in.
Exportable Audit Log
On Pro, review every action newest-first with the file, reason, and detection source, and export to CSV for auditors. A read-only panel on each issue is free and shows what FileWarden did.
In-Jira Notifications and Digest
Get a tracking-issue notification with an @mention when something is blocked, plus a daily compliance digest on Pro - no Slack or email needed, nothing leaves Atlassian.
Duplicate and Count Limits
Cap how many attachments an issue may hold, and block re-uploads of the same file - by filename, or by byte-identical content using a SHA-256 hash computed on Atlassian.
Block a Workflow Transition
Add the FileWarden validator to a transition and a disallowed attachment stops the issue from moving on, instead of only being cleaned up afterwards. It fails open, so it can never wedge a workflow.
Rovo Compliance Agent
On Pro, ask the FileWarden agent in Rovo what was removed, quarantined, or flagged over a window, or have it author a per-project block rule from the conversation. Admin-only, and every action re-checks that server-side.
Set a policy, roll it out, prove it.
Set a Policy
Start from a compliance template or build your own: allowlist or blocklist by extension, MIME type, filename pattern, or maximum size, and on Pro turn on the secret and PII content scan. Apply it globally, or per project on Pro.
Roll Out Safely
Use Monitor mode to log what would be removed, set a grace period, and exempt trusted bot uploaders before you enforce. On Pro, run a one-time scan of existing attachments to clean up violations that predate install.
Auto-Remediate
FileWarden removes violations the moment they land - or quarantines them on Pro - posts a comment explaining the policy, and notifies a tracking issue with an @mention.
Audit and Export
On Pro, review every action newest-first in the audit log, get a daily compliance digest, and export to CSV for auditors. A read-only panel on each issue is free.
Start free, upgrade for depth.
A single paid plan with a free tier. Enforcement, Monitor mode, and the per-issue panel are free; the secret and PII content scan, per-project rules, quarantine, and the exportable audit log are Pro.
Free
Unlicensed- Global policy by extension, MIME type, filename, or size
- Per-issue attachment count limit and duplicate blocking
- Compliance policy templates and the in-admin policy simulator
- On/off enforcement, Monitor mode, and grace period
- Trusted uploader and Jira group exemptions
- Automatic remediation on every upload path
- Workflow validator that blocks a transition on a disallowed file
- Confluence attachment governance - executable blocklist, files go to Space Trash
- In-Jira notifications and read-only per-issue panel
Pro
Active or trial license- Everything in Free
- Secret and PII content scan inside text, PDF, and Office files
- Signature check for types renamed to slip past their extension
- Per-project and per-Jira-group rule overrides
- Reversible quarantine and restore
- FileWarden Compliance agent in Rovo, admin-only
- One-time scan of attachments that predate install
- Compliance audit log with CSV export and daily digest
Eight scopes, and nothing leaves Atlassian.
FileWarden runs entirely on Atlassian Forge with no external egress. It governs files by filename, declared MIME type, and size, and optionally scans text, PDF, and Office files for leaked secrets and PII - all on-platform. The matched value is never shown or logged, and nothing leaves Atlassian.
read:jira-workRead issues and attachment metadata, read attachment content for the scan, list projects, and check the caller's ADMINISTER permission.
write:jira-workRemove or quarantine violating attachments and post the policy comment that explains the rule.
storage:appForge KVS for policies, the audit log, idempotency markers, and settings. No external storage.
read:jira-userResolve an uploader's Jira group membership so rules and exemptions can be scoped by group. Read only.
read:confluence-content.summaryRequired by the Confluence attachment product event that triggers governance there.
read:attachment:confluenceList and read Confluence attachments to evaluate them against the policy.
delete:attachment:confluenceMove a disallowed Confluence attachment to Space Trash, where it stays recoverable.
write:comment:confluencePost the footer comment that explains why an attachment was removed.
100% on Atlassian
No external servers
No data egress
Data residency honored
Value never logged
Content scan stays on-platform
Questions, answered.
For most policy decisions, no - it governs by filename, declared MIME type, size, count, and duplicates. As an optional Pro layer, FileWarden runs a content scan inside text, PDF, Word, Excel, and PowerPoint files, looking for leaked secrets and PII such as AWS keys, private keys, GitHub, Slack and Google tokens, JWTs, credit cards, US SSNs, and IBANs. The scan runs on Atlassian with zero external egress, and the matched value is never shown or logged. There is no antivirus engine and no OCR, so an image-only or encrypted document is treated as unreadable rather than as a match.
Inside text, PDF, and Office files (Word, Excel, PowerPoint) it matches common leaked-credential and PII patterns: AWS access keys, private key blocks, GitHub personal-access and OAuth tokens, Slack tokens, Google API keys, JSON Web Tokens, high-entropy secret assignments, credit card numbers, US Social Security numbers, IBANs, and email addresses. It runs entirely on Atlassian Forge and never shows or logs the matched value - only that a match was found.
Yes. Portal and email attachments are checked like any other issue, so a customer can't slip an executable, a leaked secret, or an oversized dump into your service desk queue.
Confluence is a separate Forge installation with no admin page of its own, so it runs the seeded default policy and only that: it blocks executables attached to pages and blogs, moves them to Space Trash where they stay recoverable, and posts a footer comment explaining why. Tuned rules, the secret and PII scan, the signature check, quarantine, per-project and per-group rules, and the grace period are Jira features - if you need attachment governance shaped to your own policy, that is the Jira side of the app.
Yes. Monitor mode logs what would be removed without deleting anything, and a grace period gives uploaders time to fix a violation before enforcement kicks in - so you can prove the policy is right before you switch it on.
By default a violation is removed and recorded in the audit log. On Pro you can quarantine instead of delete, which is reversible: restore the attachment if the block was wrong. You can also run a one-time scan of existing attachments to clean up violations that predate install.
Free includes the global policy, compliance templates, on/off, Monitor mode, the grace period, uploader exemptions, the attachment-count limit and duplicate blocking, the workflow-transition validator, automatic remediation, and the per-issue panel. Pro adds the secret and PII content scan, the signature check for renamed file types, the one-time scan of existing attachments, per-project and per-Jira-group rule overrides, reversible quarantine and restore, the Rovo compliance agent, and the compliance audit log with CSV export and daily digest.
Yes. You can cap how many attachments an issue may hold, and block a file that is already attached - either by filename, or by byte-identical content using a SHA-256 hash computed on Atlassian. Content-based duplicate detection runs on the background sweep rather than at upload, so a large file never delays the attachment.
Yes. Add the FileWarden validator to a transition in a company-managed or team-managed project and the issue cannot move on while it still holds an attachment your policy disallows. The validator fails open - if the app is off, in Monitor mode, or anything errors, the transition is allowed, so it can never wedge a workflow.
Yes. On Pro, the FileWarden Compliance agent in Rovo answers what was removed, quarantined, or flagged over a time window and can author a per-project block rule from the conversation. It is admin-only and every action re-verifies that on the server, so the agent cannot be talked into changing a policy.
No. FileWarden runs 100% on Atlassian Forge with no external egress and no sub-processors - including the content scan, which runs on-platform. Data stays within Atlassian and data residency is honored.
Eight scopes: four for Jira and app storage, four for Confluence. On Jira it reads issues and attachment metadata - and, for the Pro secret and PII scan, attachment content - to apply your policy, removes or quarantines violations, posts the policy comment, and reads an uploader's group membership so rules and exemptions can be scoped by Jira group. On Confluence it reads attachment metadata to block executables and moves them to Space Trash, with a footer comment. Its policies, audit log, and settings live in Forge storage, and everything runs on Atlassian Forge with no external egress.
Want something like FileWarden?
KUBERSTAR designed and built FileWarden. Tell us what you have in mind and the same team can build it for you.