Secure Fields · a Jira Cloud app by Inorganic Games LLC

Jira Cloud App

Secure Fields — Field-Level Security for Jira

Field-level security for Jira: protected values live outside Jira's data layer and render only for the people you authorize.

Secure Fields for Jira, a padlock above the app name, with the claims: values never in Jira, every reveal audited, admin access rules.

Available now

Secure Fields for Jira is live on the Atlassian Marketplace, carrying the Runs on Atlassian badge. Install it on any Jira Cloud site, with a free trial to evaluate it first.

Free for Jira sites of up to 10 users. Above that it is $1 per user per month, billed by Atlassian alongside your other apps (annual billing is 10 months' price for 12). See the full pricing tiers .

Jira has no field-level permissions: any user who can see an issue can see every field on it, whether through the UI, the REST API, JQL search, or CSV export. Secure Fields adds a Secure Text custom field type for the values that shouldn't sit in Jira's data layer. Values entered through Secure Fields are never written to Jira's field data. They live in Forge storage on Atlassian's platform and render only for authorized groups and project roles. REST, JQL, and CSV export show only a marker token.

How it works

  • Values Jira never stores. Values entered through Secure Fields live in Forge storage, never in the Jira field itself. Issue REST payloads, JQL search, and CSV export contain only a constant [secured] marker: verified structurally, not hidden. This is not a masking layer applied on output. There is nothing in Jira to mask.
  • Deny by default: you decide who sees. Grant view and edit per field, by Jira group or project role. Every read and write is checked server-side; everyone else sees a masked placeholder. Preview access on draft rules before saving to catch typos.
  • Every reveal is auditable. The app logs each successful reveal of a protected value, each edit, and each permission-rule change: who, what, and when, never the value itself. Jira admins query the log from the app's admin page.
  • Runs entirely on Atlassian. No external servers and no data egress: the manifest declares no external domains and no remote backends. Values are encrypted at rest on Atlassian's platform, encrypted in transit over TLS 1.2+, and follow your Jira site's data residency.

Know the tradeoffs

These are consequences of the design, not defects. If any of them is a dealbreaker, this product is not the right fit. Better to find that out here than after you buy.

  • Protected values are not JQL-searchable or reportable. No filters, dashboards, or Jira reports can use them, for anyone, including authorized users. A value Jira could search would be a value Jira stores, and that is precisely what this product exists to prevent.
  • Protected values are absent from Jira backups, exports, and site migrations, because they were never in Jira. Treat Forge storage as the sole copy; an export-for-backup capability for authorized admins is on the roadmap.
  • Values are set after the issue is created. There is no create-screen entry in the current release: save the issue first, then set the protected value from the issue view. Create-time support is the top roadmap item.
  • Cloning an issue does not copy its protected value. A clone starts with nothing stored, which fails in the safe direction.

The Security Overview states these at length, along with the scope of write protection and the paths we have and have not yet tested.

Built for regulated teams

Secure Fields is a technical access control designed to support compliance programs (HIPAA, SOC 2, GDPR, ISO 27001 and similar) by keeping designated field values out of Jira's data plane and enforcing deny-by-default, server-side access rules with an access audit trail. It is not a certification, and using it does not by itself make your organization compliant with any framework. Whether and how you may store regulated data in Atlassian cloud products, including any Business Associate Agreement or equivalent, is governed by your own agreement with Atlassian; see the Atlassian Trust Center.

Documentation & policies

Contact

Secure Fields is built and supported by Inorganic Games LLC. Questions, bug reports, and private security disclosures go to support@inorganicgames.com. The app itself is installed from its Atlassian Marketplace listing.