Local execution boundary
Container parsing and rule evaluation run in a browser worker. The analyzer reads structural metadata from a GTM export and does not execute Custom HTML or fetch resources referenced by tags.
Security
The product is designed to reduce unnecessary data movement and make its operational limits explicit.
Current release status
This page describes implemented application controls. It does not claim certification, a completed security assessment, or a managed incident-response commitment.
Container parsing and rule evaluation run in a browser worker. The analyzer reads structural metadata from a GTM export and does not execute Custom HTML or fetch resources referenced by tags.
The application defines restrictive browser security headers, including a content-security policy that blocks plugins and limits document framing. The upload control accepts JSON files and enforces a 10 MB client-side size limit.
The local product mode models Owner, Editor, and Viewer roles. Viewer access blocks new container imports. For production, authorization must be enforced on the server with Clerk organization roles or equivalent permissions before data is returned or changed.
Local workspace summaries remain in the current browser until the visitor clears browser data. D1 persistence, backup rules, audit logs, monitoring, and operational ownership must be configured before using retained client data in production.