SupplyChainGuard - Privacy Policy
Last updated: 2026-08-26
The short version
SupplyChainGuard inventories third-party JavaScript on any page and checks for known vulnerabilities. The free tier runs locally. The paid tier connects to a monitoring dashboard. Anonymized crowdsourced data helps detect supply chain threats faster.
What SupplyChainGuard does
SupplyChainGuard detects every third-party JavaScript library loaded on a page, identifies versions, checks for known CVEs, verifies SRI hashes, and detects when a script’s content changes between visits. Free scan for any page, paid continuous monitoring for your perimeter.
Data collection
SupplyChainGuard does not collect your name, email, browsing history, or any personally identifiable information.
Free tier: all analysis runs locally. No data is transmitted beyond threat intelligence lookups.
Paid tier: requires an account. Monitored domain inventories and alert configurations are synced to the Excalion dashboard. Only domain-level data and script metadata (library names, versions, hashes) are stored. No page content, cookies, or user data from the monitored sites is collected.
When you opt in to crowdsourced protection, SupplyChainGuard contributes anonymized supply chain indicators to a shared database. This includes library names, versions, CDN sources, and hash mutations. It never includes the sites you visit or anything tied to you personally.
Network activity
SupplyChainGuard makes network requests for:
- CVE database lookups: checks detected library versions against known vulnerability databases
- Crowdsourced contributions (opt-in): sends anonymized library and hash data to the Excalion API
- Dashboard sync (paid tier only): syncs monitored domain configurations and scan results to your Excalion dashboard
Permissions
- activeTab: to scan the current page for third-party scripts
- storage: to save your preferences, script hash history, and cached scan results locally
- webRequest (read-only): to observe loaded scripts and their sources
Where your data lives
Free tier: all data stays in chrome.storage.local on your device.
Paid tier: monitored domain configurations and scan results are stored on the Excalion platform, associated with your account. Local preferences remain in chrome.storage.local.
If you uninstall the extension, local data is deleted automatically by Chrome. Dashboard data can be deleted from your account settings.
Third-party services
SupplyChainGuard queries CVE and vulnerability databases for library version checks. Only library names and version numbers are sent. The paid tier syncs data to the Excalion platform under your account.
Cookies and tracking
SupplyChainGuard does not use cookies and does not track you in any way.
Supported browsers
SupplyChainGuard works on Chrome, Edge, and Brave. This privacy policy applies equally to all supported browsers.
Changes to this policy
Any changes will be reflected in extension updates. The date at the top of this page will be updated accordingly.
Contact
For questions about this privacy policy: hello@excalion.io