Sensitive data scanning Enterprise Grid
Sensitive data scanning finds personal data (PII), credentials and other sensitive values that people have pasted into your workspace. Think of an AWS key dropped into a bug report, a customer's card number in a comment, or a passport number in an intake submission. You run a scan, Plane lists what it found and where, and your admins decide what to do with each finding.
Scanning runs inside your Plane deployment. Content is read from your own database and nothing is sent to Plane or to any third party.
Access
Only workspace Admins can open sensitive data scanning. Members and guests can't see the page, the findings, or the counts.
Self-hosted instances (Commercial Edition)
On a self-hosted instance, your instance admin has to set up the scanner service before anyone can run a scan. See Configure sensitive data scanning.
What gets scanned
A scan reads the plain-text content of:
- Work items (descriptions)
- Comments
- Pages
- Custom properties (text properties)
- Intake submissions
- Projects (descriptions)
Attachments are not scanned.
What it detects
Detectors are grouped into packs. Each detector has a default severity and a confidence score, and many check a checksum so that a random string of digits isn't reported as a card number.
| Pack | Detects |
|---|---|
| Global financial | Payment card numbers (Luhn-checked), IBAN, SWIFT/BIC codes |
| Global contact & network | Email addresses, phone numbers, IPv4 and IPv6 addresses, MAC addresses |
| Credentials and secrets | AWS access keys, GCP service account keys, Azure connection strings, private key blocks, JSON web tokens, connection strings with passwords, generic high-entropy secrets |
| United States | Social Security numbers, ITIN, EIN, passport numbers, ABA routing numbers |
| United Kingdom & EU | National Insurance numbers, NHS numbers, EU VAT numbers |
| India | Aadhaar, PAN, GSTIN, IFSC codes, voter IDs |
| Customer-defined | Your own regex patterns, such as internal account or customer reference formats |
How Plane handles the values it finds
Plane never stores, logs or displays the sensitive value itself. A finding records where the value is (the work item, page or comment and the position in the text), which detector matched, its category, severity and confidence. To recognise the same value across scans, Plane keeps a one-way fingerprint of it, not the value. To see the actual text, open the source item.
Open sensitive data scanning
Go to Workspace settings → Sensitive data scanning. The page has three tabs: Scan, Detectors and Allow list.
If the page says Sensitive data scanning isn't enabled, your plan doesn't include it. If it says Sensitive data scanning isn't set up, the scanner service isn't running or isn't reachable on a self-hosted instance. Ask your instance admin to follow Configure sensitive data scanning.
Run a scan
- Open the Scan tab and click Run scan.
- In Configure scan, pick the scope:
- Projects: all projects, or only the ones you select.
- Content types: all types, or a subset such as only pages and comments.
- Only content updated between: all time, the last 7, 30 or 90 days, or a custom date range.
- Rate limit (rows per second): how fast the scanner reads from the database. Lower it on a large workspace if you want to keep load on the database down during working hours.
- Click Run scan.
The scan runs in the background, so you can keep working. When it finishes, Plane shows a notification with the number of findings.
While a scan runs you can Pause, Resume or Cancel it. Cancelling keeps the findings recorded up to that point. If a scan fails partway, nothing in your workspace changes, and you can run it again.
Scan history
The Scan history table lists every scan with who started it, when, which projects it covered, its result and its status. Open Scan details on a row to see that scan's findings, or use the row menu to Rerun scan with the same scope or copy a link to it.
Review findings
Each finding shows what was found (the detector, such as Payment card number), where it was found, severity, confidence and status. Click the location to open the work item, page or comment that contains it.
Filter findings by category, severity, status, detector, project and content type. Turn on Group by secret to collapse every occurrence of the same value into one row. This helps when one leaked key appears in twenty comments. Grouped rows count locations across the whole workspace, not only the current scan.
Severity and categories
Severity is Critical, High, Medium or Low. Each detector has a default, which you can override on the Detectors tab. Categories group findings by kind: financial instruments, government identifiers, credentials and secrets, contact data, and customer-defined.
Triage a finding
Use the Actions menu on a finding:
| Action | Result |
|---|---|
| Mark as in review | Status changes to In review. Use it while someone cleans up the source. |
| Mark as non sensitive | Status changes to Not sensitive. You can add a note explaining why. |
| Mark as non sensitive and add to allow list | Marks the finding not sensitive and creates an allow-list entry, so future scans skip the same value. Other open findings with the same value are marked not sensitive too. |
| Mark as resolved | Status changes to Resolved once the value has been removed from the source. |
Plane doesn't edit or redact your content. To remove a leaked value, edit the source item, and rotate the credential if it was a secret.
When you rescan, findings whose value no longer appears in the source become Stale.
Export findings
Click Export CSV to download findings for offline review or for an auditor. The export covers the whole workspace and applies the severity, category, status, detector and project filters. It doesn't apply the search box or the content-type filter. The file contains locations and metadata only, never the sensitive values. The download link works once and expires after 15 minutes.
Tune detectors
The Detectors tab lists every detector, grouped by pack. For each one you can:
- Turn it on or off for the workspace. Turn off packs that don't apply to you, such as India government IDs for a team with no Indian customers.
- Set Min confidence. Findings below that score aren't reported. Raise it if a detector is noisy.
- Set a Severity override to replace the detector's default severity.
Changes apply to the next scan.
Add a custom pattern
Use custom patterns for identifiers specific to your company, such as ACCT-[0-9]{8}.
- On the Detectors tab, click Add custom pattern.
- Enter a Name, the Regex pattern, a Category, a Severity and a Base confidence.
- Paste sample text under Test patterns and click Test to see what the pattern matches. The sample text isn't saved.
- Click Create pattern.
Plane rejects patterns that don't compile, that match an empty string, or that are too complex.
Maintain the allow list
The Allow list tab holds values that future scans never report. Use it for test card numbers, your own support email domain, or a demo project full of fake data.
Click Add entry and choose an entry type:
| Entry type | Suppresses |
|---|---|
| Literal value | One exact value, for example 4111 1111 1111 1111 |
| Regex | Any value matching the pattern |
| Domain | Email addresses on that domain |
| Project | Every finding in the selected project |
An entry can apply to the whole workspace or to one project. Add a Reason so teammates know later why the value is safe to ignore. Deleting an entry means matching values are reported again in future scans.
Audit trail
Plane records every scan you start, every triage decision, every detector or allow-list change, and every export and download, along with who did it and when.

