Documentation
Install, scan, review, redact: everything an administrator needs to run PII Guard.
Install
Install from Atlassian Marketplace for Jira and/or Confluence; each product is installed separately and has its own settings and findings. Open Jira settings → Apps → Claervo PII Guard, or Confluence settings → Claervo PII Guard.
Scan
Press Scan now for the first full scan. Afterwards the daily scan is incremental and real-time checks run within a minute of every create or update. Manual scans run in batches bounded by the request budget in Settings.
Detection
Built-in rules cover identity numbers (Turkish TC Kimlik, US SSN, Brazil CPF, India Aadhaar and PAN, Netherlands BSN, Canada SIN, Poland PESEL, Germany Steuer-ID, France NIR, Italy Codice Fiscale, Spain DNI/NIE, UK National Insurance, Sweden personnummer, passports), financial data (IBAN, payment cards), contact data (email, phone) and credentials (private keys, AWS, GitHub, Slack, Stripe, Google keys, JWT, passwords, generic secrets). Checksums and nearby keywords raise confidence; matches below the minimum confidence are ignored.
- Policies → Detection rules: turn rules on or off and set the minimum confidence.
- Policies → Custom patterns: add regular expressions for your own identifiers.
- Policies → Allowlist: exact values (stored hashed), patterns or company e-mail domains that should never be reported.
- Policies → Scope and fields: limit scanning to projects or spaces and choose which fields are read.
- Policies → Try the policy: paste a sample and see what would be flagged.
Act on findings
Findings show severity, category, a masked sample, confidence and a link to the item.
- Redact replaces every detected value in the affected field with a marker such as [REDACTED IBAN]. The original text is not kept; the action cannot be undone by the app.
- Restrict adds the configured label (default pii-review) and, in Jira, an optional security level id from Settings. The app needs the Set issue security permission in the project for the level to apply.
- Dismiss records accepted risk; Reopen reverses it.
Reports and audit
Reports offers a printable compliance summary and CSV exports of open or all findings with masked samples only. Audit lists scans, redactions, restrictions, reviews and configuration changes with actor and timestamp.
Data and removal
Settings → What the app stores lists everything kept in Forge storage. Settings → Reset app data removes it; uninstalling the app deletes all stored data.