Analysis boundaries

Know where analysis runs and what is retained.

Published artifacts, installed extensions and private uploads have different boundaries. The product keeps the source, execution policy and analysis limitations visible.

Published extension

Disposable isolated runner

Deep Scan downloads one exact registry artifact, performs static analysis, signs the result and discards the runner. Extension entrypoints and lifecycle code are never launched.

Exact versionStatic onlySigned result
Installed extension

Remains on the user machine

A website cannot enumerate local IDE installations. Local inventory is inspected only by a user-initiated local analysis workflow, and a report leaves the machine only when the user explicitly exports or uploads it.

User initiatedPortable report
Stored intelligence

Public evidence, private account data

Published-artifact reports are public and shareable. Personal watchlists, scan requests and account data are protected by authenticated row-level access controls.

Public artifactsPrivate workspace

Analysis guarantees

Boundaries the product will not blur.

Preflight is not Deep Scan

Instant capability hints never produce a security approval.

Identity is not safety

Popularity and publisher verification cannot override artifact evidence.

Capability is not malware

Network, filesystem and process APIs require purpose and evidence context.

Incomplete is not allow

A missing required analyzer prevents a complete decision.

Verification boundaries

Read the detection catalog and published limitations.

Rules, evidence classes, coverage and benchmark limitations are described in the product without overstating external reviewability.

Detection catalog Validation evidence