Packaged execution
Extension JavaScript, CSS, service catalogs, and UI resources ship inside the extension package. No developer-hosted executable code is loaded at runtime.
SiteEgress minimizes retained data, uses packaged code, treats page-derived evidence as untrusted, and clearly describes what browser-based inspection cannot observe.
Extension JavaScript, CSS, service catalogs, and UI resources ship inside the extension package. No developer-hosted executable code is loaded at runtime.
이름 전용 분류, 스키마 메시지, 증분 DOM 검색, 활성 상태에서만 Geo 관찰.
Reports, evidence, queues, destinations, caches, and history are capped to reduce denial-of-service and memory-growth risk.
Messages from page context are schema-validated, rate-limited, sanitized, and bound to Chrome sender and document identity where available.
Externally derived labels are escaped, dynamic identifiers are minimized, CSV exports are protected against formula injection, and HTML exports use a restrictive CSP.
시간 창과 보존 수를 제한하고 동적 값을 정리하며 영수증에 제한적 CSP를 적용합니다.
Geo Insights deduplicates public server IPs, excludes private ranges, limits concurrency, discards raw IPs, and stores only country-level aggregates.
SiteEgress cannot see server-to-server transfers, browser-internal pages, every service-worker request, encrypted body contents, or a recipient's later data use.
Fixed extension IDs, dual opt-in, schema validation, origin scoping, bounded caching, and field projection protect the optional peer channel.
Send security reports to [email protected] with the affected version, reproduction steps, impact, and a safe proof of concept. Do not access or retain data that is not yours. We will acknowledge valid reports and coordinate remediation and disclosure timing.
Contact security