Polymetis Apps provides Forge‑based security tools for Atlassian Cloud, offering a PII Protection app that continuously scans Jira and Confluence content for sensitive data and a API Key Manager that creates time‑limited, read‑only, scope‑restricted keys for granular API access. Both solutions run entirely within the Atlassian environment, helping administrators automate data loss prevention, meet compliance requirements, and reduce the risk of credential exposure.
Funding
Funding not disclosed
Founders
Product
Problem
Organizations using Jira and Confluence Cloud often store user‑generated content that may contain personally identifiable information (PII), passwords, API keys, or other credentials. Because this data is entered manually, it can be overlooked, leading to accidental exposure, compliance violations, and increased attack surface. Additionally, Atlassian’s native API tokens are tied to a user’s full permissions across all cloud instances, making it difficult to enforce least‑privilege access for integrations.
Solution
Polymetis Apps offers two Forge‑based solutions that run entirely within Atlassian Cloud, eliminating the need to export data to external services. The PII Protection app continuously scans string fields, comments, and page content in Jira and Confluence for configurable patterns such as credit‑card numbers, passwords, and API keys, and surfaces findings to administrators through a dedicated UI. Findings can be acted upon manually or via automated actions like notifications or page deletion. The API Key Manager app enables administrators to create time‑limited, read‑only, and scope‑restricted API keys that apply to a single Jira or Confluence instance, decoupling integration credentials from user permissions and allowing precise control over which REST endpoints may be accessed. Together, these tools automate data loss prevention and enforce granular API security, helping teams meet privacy regulations and reduce the risk of data breaches.
Target Audience
Primary customers are Jira and Confluence Cloud administrators, security and compliance teams, and DevOps engineers who need automated data loss prevention and fine‑grained API access control for their Atlassian environments.
Features
- Real‑time scanning of Jira issue fields, comments, and Confluence page content for over a dozen built‑in PII patterns, with support for custom checks
- Findings displayed in an admin‑only table with direct links to the offending issue or page for quick remediation
- Configurable classification levels (e.g., Top Secret, Secret, Public) and automated actions such as alerts, page deletion, or classification updates
- Time‑limited API keys (default 30 days) that automatically expire and can be revoked at any time
- Scope‑level restrictions allowing keys to be limited to specific REST endpoints or HTTP verbs (e.g., read‑only GET)
- Instance‑bound keys that apply only to the Jira or Confluence Cloud instance where the app is installed, preventing cross‑instance privilege leakage
- Built on Atlassian Forge, ensuring all processing and data storage remain within the Atlassian cloud environment