Know what's installed. Block the risky ones.
Secto lists the extensions across your managed browsers and blocks the ones you don't allow.
Animation: an employee adds an AI writing extension that asks to read and change all data on all websites. Secto blocks the install by policy and records the attempt.
Where the risk comes from
Extensions run inside the pages your team opens.
- 01Self-service
Employees install extensions without review
Unless the browser is locked down, extensions install from the store in seconds, often with no review by IT.
- 02Broad access
One permission covers every site
Many extensions can read everything in the tab, from email to admin consoles.
- 03Silent updates
Trusted extensions can turn malicious through updates
In December 2024, attackers pushed malicious updates to more than 30 extensions, including Cyberhaven's.
- 04Your decision
Secto enforces your decisions
You approve or reject each extension, and Secto applies it across your managed browsers.
Extension control
What Secto does.
- Detects
- New installs, updates and permission changes
- The employee sees
- A notice when an install is blocked
- Your security team gets
- One inventory of extensions on Chrome, Edge and Firefox
- Rollout
- Allow or block, with or without a notice
Talk to the Secto team.
See Secto in action, from the policy console to the employee’s browser.
Frequently asked questions
Something else?
Talk to a security engineer about your browsers, identity provider and rollout.
Talk to our team- Chrome and Edge get the inventory and blocking. Firefox gets the inventory. Both apply on the managed devices Secto is deployed to.
- Secto turns it off in Chrome or Edge, and the employee sees a notice explaining why.
- You choose. A common setup blocks them until someone approves them.