← ExtensionOps

Security architecture

Customer code and publishing identity remain customer-owned.

Control plane, not execution plane

Public prospect code is statically inspected only. Customer build and Chrome runtime execute on the customer's GitHub-hosted runner.

Customer-owned publishing identity

Chrome Web Store credentials stay in the customer's GitHub Environment / Google Cloud identity. ExtensionOps does not require a central long-lived publishing secret.

Safe Default

The default workflow is scan → PR → customer validation → customer merge. Autopilot requires explicit opt-in and only applies to deterministic low-risk transformations.

Evidence chain

Every release finding is tied to rule version, policy source, evidence, code, patch, tests and later CWS outcome.

No AI authority

AI can explain or propose. It cannot mark a source-code change safe for automatic release.