SiteEgress compliance

Compliance mapping.

This page maps product behavior to common review questions. Legal applicability depends on the publisher, user, deployment, jurisdiction, and use case.

本ページは製品の取り組みを説明するもので、認証や法的見解ではありません。

TopicProduct practiceEvidence and boundary
Single purposeWebsite privacy and browser-visible data-flow inspectionProduct pages, manifest description, and extension UI use the same narrow purpose.
URL クエリ最小化サニタイズ済みパラメーター名のみ値は検査・保持しません。
Data minimizationRetain metadata and categories instead of typed valuesNo passwords, form values, Cookie values, storage values, bodies, or raw destination IPs in reports.
User choiceOptional history and Geo InsightsBoth features are off by default and can be cleared or disabled.
ユーザー主導の比較選択前後のチェックポイントとローカル証跡同意UIを自動クリックせず、法的証明として表示しません。
TransparencyExplainable evidence types, score limits, permissions, and third-party lookupPrivacy policy names ipwho.is and explains country-location limitations.
Limited useAudit data is used only for the product's user-facing purposeNo sale, advertising profile, creditworthiness use, or unrelated transfer.
SecurityPackaged code, bounded data, sanitization, and restrictive exportsSecurity page and responsible disclosure channel document the controls and limitations.
Optional local bridgeDual opt-in and minimized evidence exchange with Agent GuardNo new Chrome permission; no value-bearing content or raw IP addresses; peer context cannot rewrite the audit.
Reference frameworks

How the product relates to common review questions

Chrome Web Store

The published listing, permission justifications, data-use disclosure, privacy policy, screenshots, and extension behavior should remain consistent.

GDPR concepts

The design supports data minimization, purpose limitation, transparency, user choice, and local deletion. This is not a determination that a user or publisher is compliant.

CCPA/CPRA concepts

SiteEgress does not sell or share audit data for cross-context behavioral advertising. Applicability and controller/business duties remain case-specific.

Enterprise review

Organizations should separately assess browser policy, approved extensions, third-party lookup rules, retention, legal basis, and incident-response requirements.