Data handling

Know what the service receives and retains.

Published artifacts, private package previews, imported reports, and account workspaces have different data boundaries.

Published extensions

Registry metadata and exact-artifact analysis may be stored as public intelligence, including versions, hashes, normalized findings, dependencies, files, coverage, and scanner identity.

Private VSIX preview

The hosted preview endpoint processes the uploaded package in request memory and returns its result to the browser. The endpoint does not write the uploaded package or preview result to the product database.

Account workspace

Authentication protects personal watchlists, scan requests, alert state, notification preferences, and delivery channels. Public artifact reports remain available without sign-in.

Before uploading

Use the correct analysis boundary.

For proprietary packages, review the hosted-preview limitations or use a local scanner workflow before sending any artifact to a third-party service.

Read analysis boundaries