Confirm Sensitive data is not stored if Server Side Scrubbing rules are defined on Sentry Dashboard
- Dominant language
- Python
- Stars
- 44.8k
- Forks
- 4.9k
- Avg merge
- 21h 10m
- Merged PRs (30d)
- 635
Description
### Environment
SaaS (https://sentry.io/)
### What are you trying to accomplish?
We're exploring the Sever-side PII scrubbing that sentry provides to filter sensitive data. We want to ensure that sensitive data doesn't get stored anywhere in Sentry or its servers.
### How are you getting stuck?
Technically, if we define the scrubbing rules on the Sentry dashboard, there would be sensitive data sent to Sentry. Then Sentry would scrub the sensitive data once it reaches their servers.
We want to confirm that if scrubbing rules are defined on the Sentry dashboard, Sentry will not store PII anywhere in your systems, such as for auditing purposes, temporary processing, 3rd party systems etc.
### Where in the product are you?
Settings - Security & Privacy
### Link
_No response_
### DSN
_No response_
### Version
_No response_
Contributor guide
Research direction
Start in Settings - Security & Privacy and review the server-side PII scrubbing behavior described in the issue. Determine whether data is retained during processing, for auditing, or by third-party systems, then document a definitive answer about whether dashboard-defined rules prevent PII storage.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100