Security

Security

Last updated: July 5, 2025  ยท  Report issues to getchatbridge@gmail.com

Our security commitment

Security is a core design principle of ChatBridge, not an afterthought. We built the extension with a local-first architecture specifically to minimize the attack surface and keep your data under your control at all times.

Security pillars

๐Ÿ”’

Local-first storage

All data lives in your browser. No ChatBridge servers ever receive your conversation content.

๐Ÿ”‘

No key storage

Your AI provider API keys are stored only in your local browser storage and never transmitted to us.

๐Ÿ›ก๏ธ

Minimal permissions

ChatBridge requests only the Chrome permissions it absolutely needs to function.

๐Ÿ‘๏ธ

Open source

Our full source code is publicly auditable on GitHub. No hidden backdoors.

Permissions explained

ChatBridge requests the following Chrome permissions and nothing else:

We do not request tabs, history, bookmarks, cookies, or any other broad permissions.

Cloud Gateway security

If you choose to use the optional Cloud Gateway (Cloudflare Workers proxy), the following protections apply:

Content Security Policy

The extension enforces a strict Content Security Policy on all extension pages:

Responsible disclosure

If you discover a security vulnerability in ChatBridge, please report it responsibly before disclosing it publicly. We take all security reports seriously and will respond promptly.

Report a vulnerability We aim to respond within 48 hours.