Security
Security by architecture, not by promise
DevOps Navigator is a static client-side application. That design choice is the security model: there is no backend to compromise, no database to leak and no third-party analytics to collect data.
How your token is handled
When you sign in, your personal access token and organization URL are stored in this browser's storage (session storage by default, local storage if you choose “keep me signed in”). They are never sent to a DevOps Navigator server - there isn't one.
Depending on how the site is deployed, an operator-provided key may be used to obfuscate the stored value. This protects against casual inspection of browser storage; it is not encryption that protects the token from someone who controls your browser or your machine. If you want zero persistent traces, use session storage (the default) and sign out when you finish.
Where data goes
All API requests are made directly from your browser to Microsoft's Azure DevOps endpoints (dev.azure.com and related Azure DevOps hosts) using the official REST APIs. The token is sent as a credential on those requests and is never placed in URLs, query strings, logs or analytics events.
Read-only access
DevOps Navigator only issues read requests. It cannot create, edit or delete work items, push code, check in changes or change any Azure DevOps setting. A token scoped to read permissions is all it needs.
Defense in depth
- A strict Content Security Policy restricts where the browser may connect and what it may load.
- Azure-authored rich text (descriptions, comments) is sanitized before rendering, and image attributes are escaped.
- No third-party scripts, trackers or analytics are embedded.
- Signing out clears your credentials from browser storage immediately.
What we ask you to do
Use a token with read-only scopes and a sensible expiration (30-90 days). Do not paste a full-access token into any third-party tool, including this one - a read-only token is all the dashboard requires.