Catalog isolation
Public list, search, category, sorting, and detail requests read Marketplace’s own catalog database. They do not enumerate packages through the emploidai backend and cannot access tenant installation state.
Package integrity
Installable package records include an immutable SHA-256 digest, expected byte size, validation status, and compatibility metadata. Marketplace serves only verified records. emploidai verifies the downloaded size, digest, compatibility, and package identifier again before handing the artifact to the plugin runtime.
Service authentication
Install manifests, package downloads, update resolution, and review writes are private service-to-service endpoints protected by a shared service credential. Public clients cannot download package artifacts through catalog APIs.
Publisher labels
“Official” and “partner” describe publisher verification. Community listings are not presented as publisher-verified. Package validation is a separate technical signal and does not endorse a publisher’s business practices.
Responsible disclosure
Report a suspected vulnerability through your emploidai support channel. Include the product identifier, version, affected tenant, reproduction steps, and impact. Do not include production credentials or unrelated personal data.