Plugin specialist kit · ECZ-ID Plugin
ECZ-ID Marketplace App Security & Enterprise Approval Kit
Turn publisher, permission, release and marketplace evidence into an enterprise-review pack.
Built for plugins, extensions, actions and store apps that must explain who publishes them, what they can access and how their release evidence can be checked.
- Type
- Digital product
- Price
- Not restated on this site; TrustOps publishes the current price and availability
- Acquired and paid in
- TrustOps
- Operated in · proved by
- Dashboard · Resolver
The problem
Why it matters.
Before an enterprise allows a plugin, extension or store app, a reviewer asks who publishes it, what it can access, where it is listed and how releases are controlled. Publishers answer from scratch for every customer, and approvals stall.
Built for
- Plugin publishers
- Marketplace apps
- Enterprise extension approval
What changes
- Faster enterprise review
- Reusable permission and publisher evidence
- Clearer release provenance
What you receive
Concrete deliverables, not a vague trust score.
- Publisher identity evidence
- Permission and scope review
- Marketplace and release evidence
- Buyer-facing approval pack
- Publisher
- Organisation, Parent tier and the plugin's ECZ-ID
- Permissions
- Requested scopes and access, with the reason for each
- Listings
- Every marketplace listing, recorded as a declared binding on the one identity
- Releases
- Release and provenance evidence, where supplied
- Gaps
- Open items a reviewer will ask about, stated plainly
Illustrative structure. The pack is assembled from your evidence; the Resolver remains the live proof.
How it works
A short path from need to something usable.
Select the plugin.
Map publisher and permission evidence.
Resolve gaps.
Package the result for review.
How it relates to your Passport
The kit builds on the free Plugin Passport: one identity for the plugin, each listing recorded as a declared binding, the publisher on the record. It organises the evidence a reviewer needs around that identity and points them to the Resolver for current proof.
Use cases
- Getting an editor extension onto an enterprise allow-list.
- Answering a customer security review for a store app.
- Giving a marketplace reviewer one consistent publisher story.
Tiers and price
Price and availability
Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal. This site does not restate this product's price; TrustOps publishes its current tiers, price and availability, and shows them before anything is bought.
How it is arranged
TrustOps acquires
TrustOps publishes the tiers and holds payment and entitlement whenever it is offered.
Dashboard operates
Once you hold it, it appears in your Dashboard, where you operate it.
Resolver proves
Public facts stay on the Resolver; holding it never changes what a record proves.
Privacy, security and evidence
What is collected, published and kept.
- You choose what goes into the pack and what is published.
- Permission and scope descriptions come from you; the kit does not inspect users' environments.
- The kit supports review; it does not guarantee marketplace or enterprise approval.
Boundaries
The claims stop here.
- The kit supports review; it does not guarantee marketplace or enterprise approval.
Integrations and questions
Works with what you already run.
- Marketplace listings and repositories, recorded as declared bindings on the plugin's ECZ-ID. The connectors for them are Planned.
- Parent VERIFIED or ASSURED for publisher assurance.
- SBOM and LedgerCore evidence where you hold them.
- Will this get my plugin approved?
- It makes review faster and more consistent. It does not guarantee marketplace or enterprise approval.
- Do I need a paid Parent tier first?
- No. Your organisation's ECZ-ID Business Passport — Declared — FREE is enough to start; VERIFIED or ASSURED strengthens the publisher evidence when a reviewer needs it.
- Where do I buy it?
- In TrustOps, which owns purchase, payment, fulfilment and entitlement.
Related
- Workflow bundleECZ-ID Extension Publisher Assurance BundleGive buyers a consistent publisher and release story across distribution ecosystems.Read more
- Software supply chainSBOM & software-composition evidenceTurn software composition and provenance into evidence a buyer can actually review.Read more
- CounterpartyDCI — Digital Counterparty InfrastructureMake a digital counterparty easier for people and machines to identify, inspect and re-check.Read more
Keep the identity free. Everything above it is optional.
Your Plugin Passport stays free. ECZ-ID Marketplace App Security & Enterprise Approval Kit sits above it; TrustOps shows its current state.
