Security
Built to observe, not to control.
ExtVerdict tells you what is installed across your organisation and what is known about it. It is designed so that seeing your fleet never requires giving ExtVerdict control of it.
Read-only by design.
The ExtVerdict Agent observes and reports. It does not uninstall software, modify policy or execute remote commands. Remediation stays in your approved management workflows.
- The Agent does not uninstall or disable software.
- The Agent does not change browser, IDE or device policy.
- The Agent does not execute remote commands.
- The Agent does not open a remote shell.
“Read-only” describes what the Agent does to your endpoints: it does not change the software or policy it reports on. Like any installed software, it keeps its own local state and logs, and it communicates outbound to report.
Narrow collection
The Agent reads what is needed to inventory extensions and the browsers and IDEs they run in:
- Machine name, operating system and version, and the signed-in operating-system user name
- Installed browsers and IDEs, with version and release channel
- Installed browser extensions and IDE plugins: identifier, name, version and, where the platform exposes them, publisher, permissions and enabled state
It does not collect:
- Browsing history or page content
- Cookies or saved passwords
- The contents of your files or source code
It reads fixed, vendor-documented locations and never launches the browsers or IDEs it inventories.
Reporting and credentials
- The Agent reports over HTTPS and refuses unencrypted HTTP to any remote endpoint.
- Each organisation issues its own ingestion tokens. ExtVerdict stores them only as hashes, and an administrator can revoke one at any time.
- The organisation a report belongs to is derived on the server from its token, never from anything the report itself claims.
Organisation isolation
- Customer data is scoped to its organisation, and that scope is enforced in the database itself.
- Portal access is checked against organisation membership on the server for every request.
- Portal sessions and Agent credentials are separate: neither is accepted in place of the other.
Observation is separate from enforcement
ExtVerdict does not connect to your device-management platforms. Remediation guidance, rolling out across supported platforms, tells you what to change and how, in the tools you already approve and audit. A later scan verifies the outcome from what the endpoint reports.
Honest intelligence
- Known-vulnerability findings come only from trusted sources matched to an exact extension identity and version.
- Heuristic risk is labelled as review signals, not as confirmed threat intelligence.
- Anything outside source coverage is shown as not covered. Unknown is never presented as safe.
This website
This website uses no analytics, sets no cookies and loads no third-party scripts. Contact is by email only.
Questions
For security questions, including a suspected vulnerability, email security@extverdict.com.