Security
WingMarq shows the right guide automatically when someone opens a tool, while maintaining strict boundaries around user data and document access.
Architecture
The WingMarq browser extension uses the page URL to decide whether a matching guide exists. It does not read page content, form data, cookies, or anything a user types.
- • No document content is accessed or transmitted
- • The extension runs on HTTPS pages so it can check each page address against your Marqs. The only thing it adds to a page is the small WingMarq prompt, and only where a Marq matches.
- • To notice in-app navigation on sites that may have a Marq, it watches for page updates without reading what they contain.
- • Guide links must be HTTPS and are opened in a new tab only when someone clicks them
- • From version 1.5.0, the version both stores now offer, the extension talks only to app.wingmarq.com, to fetch your workspace’s Marqs and to record Marq events. Installations not yet updated from 1.4.1 or earlier also send prompt events to Google Analytics until they update. See the IT guide for the version differences.
Data handling
WingMarq stores minimal operational data required to manage workspaces, Marqs and usage analytics.
- • Workspace configuration
- • Marq configurations (URL patterns, labels, guide titles and links)
- • Marq events: shown, opened or dismissed, with the Marq, the site’s address only (such as https://app.example.com/), the time and the extension version. Events recorded before the 2 October 2026 server update include the full page address. Events carry no user identity.
What WingMarq does not access
- • Microsoft 365 documents
- • SharePoint files
- • Email content
- • Teams messages
Responsible disclosure
If you discover a security vulnerability please report it to security@wingmarq.com.