FileWarden
Attachment governance for Jira
Block risky or non-compliant attachments and catch leaked secrets and PII across every Jira upload path - with reversible quarantine and a full audit trail.
- Runs 100% on Atlassian
- No external egress
- Full audit trail

Govern every attachment, automatically.
Govern every attachment on every upload path
Comments, descriptions, forms, custom fields, and Jira Service Management requests are all covered. The moment a violation lands, FileWarden removes it - or quarantines it on Pro - and posts a clear comment explaining which policy it broke - no manual cleanup, no gaps.
Catch leaked secrets and PII inside text files
On Pro, a lightweight, zero-egress content scan reads text files for AWS keys, private keys, API tokens, credit cards, and US SSNs. The matched value is never shown or logged - FileWarden acts as a DLP layer without anything leaving Atlassian.
Exportable audit log and per-issue history
On Pro, review every action newest-first with the file, reason, and actor, and export to CSV for auditors. A read-only panel on each issue shows what FileWarden did to its attachments, free.
Stop risky and non-compliant attachments from piling up in Jira. Jira Cloud has no pre-upload hook, so a .exe, an oversized export, or a stray secret.env can land through a comment, a description, a form, a custom field, or a service desk request - and stay there. FileWarden watches every upload path and auto-removes anything that breaks your policy - or quarantines it on Pro - posts a human-readable comment so people learn the rule, and keeps a tamper-evident audit trail. It acts as a Jira DLP layer for attachment security - governing files by type, name, and size, and scanning text files for leaked secrets and PII - with no antivirus engine and no external service.
Templates or your own rule
Start from a compliance template - block executables, block secrets, HIPAA, PCI-DSS, GDPR, or office-only - or allowlist and blocklist by extension, MIME type, filename, or size. Globally, or per project on Pro. Templates are a starting point you can tune.
Secret and PII content scan
On Pro, inside text files, FileWarden looks for AWS keys, private keys, API tokens, credit cards, and US SSNs. The scan runs on Atlassian with zero egress and never shows or logs the matched value.
Safe to roll out
Monitor mode logs what would be removed without deleting, a grace period gives uploaders time to fix a violation, and trusted bot and CI accounts can be exempted. On Pro, run a one-time scan of existing attachments to clean up what predates install.
Reversible remediation and audits
Quarantine instead of delete on Pro, then restore if a block was wrong. Every action is logged newest-first; on Pro the full audit log exports to CSV and a daily compliance digest lands on the admin page. The read-only per-issue panel is free.
Notifies inside Jira
When something is blocked, FileWarden posts to a tracking issue with an @mention and can raise a permission alert - no Slack or email needed, nothing leaves Atlassian.
Runs 100% on Atlassian
No external servers, no data egress, data residency honored - eligible for the Runs on Atlassian badge. The content scan runs on-platform too.
Everything it takes to keep attachments clean.
Block on Every Upload Path
Comments, descriptions, forms, custom fields, Jira Service Management requests, and Confluence pages and blogs are all covered. When a violation lands, FileWarden removes it - or quarantines it on Pro - and posts a comment naming the policy it broke - no manual cleanup, no gaps.
Restrict File Types
Match by extension, MIME type, filename glob, or maximum size, as an allowlist or a blocklist. Set one global policy, or per-project rules on Pro.
Secret and PII Content Scan
On Pro, a zero-egress scan reads inside text, PDF, Word, Excel, and PowerPoint files for leaked secrets and PII - AWS keys, private keys, API tokens, credit cards, and US SSNs. The matched value is never shown or logged.
Compliance Policy Templates
Apply a sensible policy in one click: block executables, block secrets, or a HIPAA, PCI-DSS, GDPR, or office-only posture. Templates are a starting point you can tune.
Quarantine and Restore
On Pro, remove violations reversibly: quarantine an attachment instead of deleting it, then restore it if the block was wrong.
Monitor Mode and Grace Period
Dry-run a policy: Monitor mode logs what would be removed without deleting anything, and a grace period gives uploaders time to fix a violation before enforcement kicks in.
Exportable Audit Log
On Pro, review every action newest-first with the file, reason, and actor, and export to CSV for auditors. A read-only panel on each issue is free and shows what FileWarden did.
In-Jira Notifications and Digest
Get a tracking-issue notification with an @mention when something is blocked, plus a daily compliance digest on Pro - no Slack or email needed, nothing leaves Atlassian.
Set a policy, roll it out, prove it.
Set a Policy
Start from a compliance template or build your own: allowlist or blocklist by extension, MIME type, filename pattern, or maximum size, and on Pro turn on the secret and PII content scan. Apply it globally, or per project on Pro.
Roll Out Safely
Use Monitor mode to log what would be removed, set a grace period, and exempt trusted bot uploaders before you enforce. On Pro, run a one-time scan of existing attachments to clean up violations that predate install.
Auto-Remediate
FileWarden removes violations the moment they land - or quarantines them on Pro - posts a comment explaining the policy, and notifies a tracking issue with an @mention.
Audit and Export
On Pro, review every action newest-first in the audit log, get a daily compliance digest, and export to CSV for auditors. A read-only panel on each issue is free.
Start free, upgrade for depth.
A single paid plan with a free tier. Enforcement, Monitor mode, and the per-issue panel are free; the secret and PII content scan, per-project rules, quarantine, and the exportable audit log are Pro.
Free
Unlicensed- Global policy by extension, MIME type, filename, or size
- Per-issue attachment count limit and duplicate blocking
- Compliance policy templates and the in-admin policy simulator
- On/off enforcement, Monitor mode, and grace period
- Trusted uploader and Jira group exemptions
- Automatic remediation on every upload path
- Confluence attachment governance
- In-Jira notifications and read-only per-issue panel
Pro
Active or trial license- Everything in Free
- Secret and PII content scan inside text, PDF, and Office files
- Signature check for types renamed to slip past their extension
- Per-project and per-Jira-group rule overrides
- Reversible quarantine and restore
- One-time scan of attachments that predate install
- Compliance audit log with CSV export and daily digest
Three scopes, and nothing leaves Atlassian.
FileWarden runs entirely on Atlassian Forge with no external egress. It governs files by filename, declared MIME type, and size, and optionally scans text files for leaked secrets and PII - all on-platform. The matched value is never shown or logged, and nothing leaves Atlassian.
read:jira-workRead issues and attachment metadata, read text attachments for the content scan, list projects, and check the caller's ADMINISTER permission.
write:jira-workRemove or quarantine violating attachments and post the policy comment that explains the rule.
storage:appForge KVS for policies, the audit log, idempotency markers, and settings. No external storage.
100% on Atlassian
No external servers
No data egress
Data residency honored
Value never logged
Content scan stays on-platform
Questions, answered.
For most policy decisions, no - it governs by filename, declared MIME type, and size. As an optional Pro layer, FileWarden runs a content scan inside text, PDF, Word, Excel, and PowerPoint files, looking for leaked secrets and PII such as AWS keys, private keys, API tokens, credit cards, and US SSNs. The scan runs on Atlassian with zero external egress, and the matched value is never shown or logged. There is no antivirus engine.
Inside text, PDF, and Office files (Word, Excel, PowerPoint) it matches common leaked-credential and PII patterns: AWS access keys, private keys, generic API tokens, credit card numbers, and US Social Security numbers. It runs entirely on Atlassian Forge and never shows or logs the matched value - only that a match was found.
Yes. Portal and email attachments are checked like any other issue, so a customer can't slip an executable, a leaked secret, or an oversized dump into your service desk queue.
Yes. Monitor mode logs what would be removed without deleting anything, and a grace period gives uploaders time to fix a violation before enforcement kicks in - so you can prove the policy is right before you switch it on.
By default a violation is removed and recorded in the audit log. On Pro you can quarantine instead of delete, which is reversible: restore the attachment if the block was wrong. You can also run a one-time scan of existing attachments to clean up violations that predate install.
Free includes the global policy, compliance templates, on/off, Monitor mode, the grace period, uploader exemptions, automatic remediation, and the per-issue panel. Pro adds the secret and PII content scan, the signature check for renamed file types, the one-time scan of existing attachments, per-project and per-Jira-group rule overrides, reversible quarantine and restore, and the compliance audit log with CSV export and daily digest.
No. FileWarden runs 100% on Atlassian Forge with no external egress and no sub-processors - including the content scan, which runs on-platform. Data stays within Atlassian and data residency is honored.
On Jira it reads issues and attachment metadata - and, for the Pro secret and PII scan, attachment content - to apply your policy, removes or quarantines violations, and posts the policy comment. On Confluence it reads attachment metadata to block executables and moves them to Space Trash. Its policies, audit log, and settings live in Forge storage, and everything runs on Atlassian Forge with no external egress.
Want something like FileWarden?
KUBERSTAR designed and built FileWarden. Tell us what you have in mind and the same team can build it for you.