Findings
Each extension finding - new detections, score changes, and resolved issues - is logged with the technical evidence behind it: code snippets, network destinations, and the specific behavior that triggered the flag.
Reporting
Findings, alerts, and enforcement actions logged with a timestamp, device, and actor. 12-month retention, exportable, with full risk history per extension.
When did this extension turn bad?
Each monitored extension in your fleet has a timeline: first seen, version updates, risk score changes, and findings. When an incident occurs, you can pinpoint the exact version and date a previously-clean extension started exhibiting malicious behavior - essential for incident response and legal discovery.
Full audit trail, no extra tooling.
Logs are available from day one.