Verified publisher identity
Vendor legal identity, authorized representative, support email, domain, and payout identity are verified before paid publication.
PlugPlayground makes permissions, data handling, vendor identity, review evidence, and lifecycle control visible before an organization approves an app.
Platform controls
Marketplace content and vendor endpoints are treated as hostile input. Sensitive controls are enforced on the server and recorded in an audit trail.
Vendor legal identity, authorized representative, support email, domain, and payout identity are verified before paid publication.
Each installation receives organization-, app-, audience-, and scope-bound credentials. Added permissions require renewed consent.
Server-side authorization is backed by PostgreSQL row-level security and negative cross-tenant tests.
Listing media is privately uploaded, type-checked, scanned, decoded, re-encoded, and served from a separate untrusted-content origin.
Vendor URLs are inspected in an isolated worker that blocks internal, loopback, link-local, metadata, and special-use network targets.
Install, entitlement, suspension, and uninstall events are signed, timestamped, replay-protected, and idempotent.
Publication workflow
Every app version moves through immutable validation and review states. Critical findings block publication.
Manifest schema, signature, domain, redirect URI, permission diff, TLS, asset, link, and secret checks.
Data access, storage, retention, deletion, incident response, and evidence are assessed against published criteria.
Reviewers test installation, core claims, configuration, support paths, and uninstall behavior.
Material updates are rescanned. Badges expire. Vulnerabilities and policy breaches can suspend or revoke an app.
Trust labels
A label never means an app is risk-free. It identifies criteria met, evidence reviewed, the review date, and when the assertion expires.
Self-attested and independently verified claims are clearly distinguished.
A badge assignment records the evidence, reviewer, approval date, expiration date, and revocation history.
Permission or data-handling changes can invalidate a badge and trigger customer action.
Customers can export current security profiles for internal procurement and review.
Security profile complete
Evidence reviewed 12 July 2026
Security reports receive a tracked case. App reviews also include abuse reporting for spam, conflicts, and manipulation.