Skip to content
PlugPlayground
Curated vendor-hosted apps. No third-party code runs on PlugPlayground.
Trust is a system, not a badge

Security evidence where marketplace decisions happen

PlugPlayground makes permissions, data handling, vendor identity, review evidence, and lifecycle control visible before an organization approves an app.

Platform controls

Defence in depth by default

Marketplace content and vendor endpoints are treated as hostile input. Sensitive controls are enforced on the server and recorded in an audit trail.

Verified publisher identity

Vendor legal identity, authorized representative, support email, domain, and payout identity are verified before paid publication.

Least-privilege authorization

Each installation receives organization-, app-, audience-, and scope-bound credentials. Added permissions require renewed consent.

Tenant isolation

Server-side authorization is backed by PostgreSQL row-level security and negative cross-tenant tests.

Quarantined uploads

Listing media is privately uploaded, type-checked, scanned, decoded, re-encoded, and served from a separate untrusted-content origin.

SSRF-safe endpoint checks

Vendor URLs are inspected in an isolated worker that blocks internal, loopback, link-local, metadata, and special-use network targets.

Signed lifecycle events

Install, entitlement, suspension, and uninstall events are signed, timestamped, replay-protected, and idempotent.

Publication workflow

No automatic path to public distribution

Every app version moves through immutable validation and review states. Critical findings block publication.

1

Automated validation

Manifest schema, signature, domain, redirect URI, permission diff, TLS, asset, link, and secret checks.

2

Security review

Data access, storage, retention, deletion, incident response, and evidence are assessed against published criteria.

3

Functional review

Reviewers test installation, core claims, configuration, support paths, and uninstall behavior.

4

Ongoing monitoring

Material updates are rescanned. Badges expire. Vulnerabilities and policy breaches can suspend or revoke an app.

Trust labels

Evidence-scoped, time-bound, and revocable

A label never means an app is risk-free. It identifies criteria met, evidence reviewed, the review date, and when the assertion expires.

Self-attested and independently verified claims are clearly distinguished.

A badge assignment records the evidence, reviewer, approval date, expiration date, and revocation history.

Permission or data-handling changes can invalidate a badge and trigger customer action.

Customers can export current security profiles for internal procurement and review.

Security profile complete

Evidence reviewed 12 July 2026

Assertion type
Marketplace verified
Scope
Version 3.8.x
Evidence
Data flow, retention, deletion, incident policy
Reviewer
PlugPlayground Trust Operations
Expires
12 July 2027
Status
Current

Report a vulnerability or marketplace abuse

Security reports receive a tracked case. App reviews also include abuse reporting for spam, conflicts, and manipulation.

Contact security