getsentry / getsentry/sentry

Confirm Sensitive data is not stored if Server Side Scrubbing rules are defined on Sentry Dashboard

Open
#108,479 3 comments 0 reactions 0 assignees View on GitHub
Product Area: Settings - Security & Privacy Waiting for: Product Owner
Dominant language
Python
Stars
44.8k
Forks
4.9k
Avg merge
21h 10m
Merged PRs (30d)
635

Description

### Environment

SaaS (https://sentry.io/)

### What are you trying to accomplish?

We're exploring the Sever-side PII scrubbing that sentry provides to filter sensitive data. We want to ensure that sensitive data doesn't get stored anywhere in Sentry or its servers.

### How are you getting stuck?

Technically, if we define the scrubbing rules on the Sentry dashboard, there would be sensitive data sent to Sentry. Then Sentry would scrub the sensitive data once it reaches their servers.

We want to confirm that if scrubbing rules are defined on the Sentry dashboard, Sentry will not store PII anywhere in your systems, such as for auditing purposes, temporary processing, 3rd party systems etc.

### Where in the product are you?

Settings - Security & Privacy

### Link

_No response_

### DSN

_No response_

### Version

_No response_

Contributor guide

Open the contributing guide

Research direction

Start in Settings - Security & Privacy and review the server-side PII scrubbing behavior described in the issue. Determine whether data is retained during processing, for auditing, or by third-party systems, then document a definitive answer about whether dashboard-defined rules prevent PII storage.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.