Sentry data sharing & exposure security checks
External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.
On Sentry, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Sentry connector needs.
Checks (7)
severity: medium Shared Issues Enabled fix difficulty: easy #
Disable public issue sharing to prevent unauthenticated access to error data
- Sign in to Sentry as an organization owner or admin
- Navigate to Settings > General (https://sentry.io/organizations/<org>/settings/)
- Locate the "Allow Sharing Issues" toggle under the Security section
- Disable the toggle so issues cannot be shared via public links
- Click "Save Changes" to apply
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.iii HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium Enhanced Privacy Disabled fix difficulty: easy #
Enable enhanced privacy mode to restrict personal data visibility to authorized members
- Sign in to Sentry as an organization owner or admin
- Navigate to Settings > General (https://sentry.io/organizations/<org>/settings/)
- Locate the "Enhanced Privacy" toggle under the Security or Privacy section
- Enable the toggle to restrict sensitive data (e.g. usernames, IPs) to members with appropriate access
- Click "Save Changes" to apply
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.iii HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium Open Membership fix difficulty: easy #
Disable open membership so new users must be explicitly invited to join teams
- Sign in to Sentry as an organization owner or admin
- Navigate to Settings > General (https://sentry.io/organizations/<org>/settings/)
- Locate the "Open Membership" toggle under the Membership section
- Disable the toggle to require explicit team invitations
- Click "Save Changes" to apply
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.iii HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium Event Attachments Access fix difficulty: easy #
Restrict event attachments access to admin, manager, or owner roles only
- Sign in to Sentry as an organization owner or admin
- Navigate to Settings > General (https://sentry.io/organizations/<org>/settings/)
- Locate the "Event Attachments" role setting under the Visibility section
- Change the minimum role to "admin", "manager", or "owner"
- Click "Save Changes" to apply the restriction
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.iii HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium Data Scrubber Disabled fix difficulty: easy #
Enable the data scrubber to automatically remove sensitive data from ingested events
- Sign in to Sentry as an organization owner or admin
- Navigate to Settings > General (https://sentry.io/organizations/<org>/settings/)
- Scroll to the "Data Privacy" section
- Enable the "Data Scrubber" toggle
- Optionally add custom scrubbing rules for fields specific to your application
- Click "Save Changes" to apply
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium Data Scrubber Defaults Disabled fix difficulty: easy #
Enable default data scrubber rules to apply standard PII removal across all projects
- Sign in to Sentry as an organization owner or admin
- Navigate to Settings > General (https://sentry.io/organizations/<org>/settings/)
- Scroll to the "Data Privacy" section
- Enable the "Use Default Scrubbers" toggle to activate Sentry's built-in PII patterns
- Click "Save Changes" to apply the default scrubbing rules to all projects
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: low Debug Files Access fix difficulty: easy #
Restrict debug file access to admin, manager, or owner roles to protect symbol files
- Sign in to Sentry as an organization owner or admin
- Navigate to Settings > General (https://sentry.io/organizations/<org>/settings/)
- Locate the "Debug Files" role setting under the Visibility section
- Change the minimum role to "admin", "manager", or "owner"
- Click "Save Changes" to apply the restriction
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.iii HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11