Skip to content

Sentry data sharing & exposure security checks

External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.

On Sentry, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Sentry connector needs.

Checks (7)

severity: medium Shared Issues Enabled fix difficulty: easy #

Disable public issue sharing to prevent unauthenticated access to error data

  1. Sign in to Sentry as an organization owner or admin
  2. Navigate to Settings > General (https://sentry.io/organizations/<org>/settings/)
  3. Locate the "Allow Sharing Issues" toggle under the Security section
  4. Disable the toggle so issues cannot be shared via public links
  5. Click "Save Changes" to apply

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.iii HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: medium Enhanced Privacy Disabled fix difficulty: easy #

Enable enhanced privacy mode to restrict personal data visibility to authorized members

  1. Sign in to Sentry as an organization owner or admin
  2. Navigate to Settings > General (https://sentry.io/organizations/<org>/settings/)
  3. Locate the "Enhanced Privacy" toggle under the Security or Privacy section
  4. Enable the toggle to restrict sensitive data (e.g. usernames, IPs) to members with appropriate access
  5. Click "Save Changes" to apply

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.iii HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: medium Open Membership fix difficulty: easy #

Disable open membership so new users must be explicitly invited to join teams

  1. Sign in to Sentry as an organization owner or admin
  2. Navigate to Settings > General (https://sentry.io/organizations/<org>/settings/)
  3. Locate the "Open Membership" toggle under the Membership section
  4. Disable the toggle to require explicit team invitations
  5. Click "Save Changes" to apply

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.iii HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: medium Event Attachments Access fix difficulty: easy #

Restrict event attachments access to admin, manager, or owner roles only

  1. Sign in to Sentry as an organization owner or admin
  2. Navigate to Settings > General (https://sentry.io/organizations/<org>/settings/)
  3. Locate the "Event Attachments" role setting under the Visibility section
  4. Change the minimum role to "admin", "manager", or "owner"
  5. Click "Save Changes" to apply the restriction

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.iii HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: medium Data Scrubber Disabled fix difficulty: easy #

Enable the data scrubber to automatically remove sensitive data from ingested events

  1. Sign in to Sentry as an organization owner or admin
  2. Navigate to Settings > General (https://sentry.io/organizations/<org>/settings/)
  3. Scroll to the "Data Privacy" section
  4. Enable the "Data Scrubber" toggle
  5. Optionally add custom scrubbing rules for fields specific to your application
  6. Click "Save Changes" to apply

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: medium Data Scrubber Defaults Disabled fix difficulty: easy #

Enable default data scrubber rules to apply standard PII removal across all projects

  1. Sign in to Sentry as an organization owner or admin
  2. Navigate to Settings > General (https://sentry.io/organizations/<org>/settings/)
  3. Scroll to the "Data Privacy" section
  4. Enable the "Use Default Scrubbers" toggle to activate Sentry's built-in PII patterns
  5. Click "Save Changes" to apply the default scrubbing rules to all projects

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: low Debug Files Access fix difficulty: easy #

Restrict debug file access to admin, manager, or owner roles to protect symbol files

  1. Sign in to Sentry as an organization owner or admin
  2. Navigate to Settings > General (https://sentry.io/organizations/<org>/settings/)
  3. Locate the "Debug Files" role setting under the Visibility section
  4. Change the minimum role to "admin", "manager", or "owner"
  5. Click "Save Changes" to apply the restriction

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.iii HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

More Sentry checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial