Caporia policies

Listing Standards

These standards apply to every capability listed on Caporia, first-party or third-party. They exist so that a buyer can understand a capability before installing it. A listing that does not meet them can be delayed, annotated, or removed.

Effective September 22, 2026 · Last updated September 22, 2026

Say what it does, and only what it does

  • Describe the capability's actual behavior in plain language: what it reads, writes, calls, and changes.
  • State what it does not do. If it reviews code but does not run it, say so.
  • Every claim must be true for the version being sold. Update the listing when the package changes.
  • Screenshots, examples, and demos must show the current version and real output.

Permissions and data

  • List every permission, network destination, file location, credential, and external service the capability uses, and why.
  • State what data leaves the buyer's environment, where it goes, and whether it is stored.
  • Do not collect or transmit more than the listing discloses.

Words you may not use about Caporia's review

Caporia's review records describe specific checks in specific environments. They are Caporia's observations, not a certification. In your listing and marketing you may not describe your package as "verified", "certified", "vetted", "approved", "independently tested", "proof", "guaranteed", "safe", or "low risk" by Caporia, and you may not imply that Caporia reproduced your results or guarantees your package. You may say that a Caporia review record exists and link to it. Caporia's own label "approved publisher" means only that Caporia admitted you to sell; it is not a statement about your packages, and you may not present it as one.

Requirements, compatibility, and recovery

  • State runtimes, versions, operating systems, and prerequisites the buyer must have.
  • State known incompatibilities and limitations.
  • Explain how a buyer removes the capability and reverses its changes.

Licensing and attribution

  • Show the license the buyer receives before purchase.
  • Identify third-party components and their licenses, and comply with them (including attribution and copyleft obligations).
  • Do not list anything you do not have the right to sell.

Support and versions

  • Provide a working support contact and respond to buyers within a reasonable time.
  • Use a version number that changes with every released change. Keep a changelog.
  • Do not remove a version buyers depend on without notice; buyers keep the version they licensed.

Prohibited content

Malware or hidden functionality; packages that infringe others' rights; packages built to produce illegal content, defraud, or evade platform or legal controls; fake reviews or fabricated evidence; and anything that violates the Publisher Agreement or applicable law.

Questions about these policies can be sent to support@caporia.co.