esdecode

Marketplace trust center

esdecode is a marketplace for source code, which means trust depends on clear rules, visible review scope and straightforward buyer and seller policies. This page collects the documents that explain how the marketplace works.

Trust badges and what they mean

Every badge on esdecode records a specific check that was carried out. None of them is a general statement of quality or safety. Each badge below lists what it confirms, how it is earned, what it does not mean, and how it can be lost.

Identity Verified

The seller has completed the platform's identity-verification process. A named person or company representative is on record with esdecode for this account.

What it does not mean

  • It does not guarantee product quality.
  • It does not guarantee seller performance or support responsiveness.
  • It does not say anything about the security of the seller's code.
How it is earned
A reviewer checks the evidence the seller submits and records the outcome. Identity documents are reviewed and are never published or stored in audit logs.
Expiry
May carry an expiry date; expired verification must be renewed.
Revocation
Revoked if the evidence is found to be false, the account changes hands, or the seller is removed from the marketplace.

GitHub Connected

The seller successfully authenticated with GitHub, proving control of that account at the time of connection. esdecode stores the immutable GitHub user ID, so the badge survives a username change.

What it does not mean

  • It does not mean GitHub reviewed, endorsed, or approved the seller.
  • It does not mean the listed product is open source.
  • It does not mean the code sold here comes from that GitHub account.
How it is earned
The seller connects their GitHub account from the seller dashboard using OAuth.
Expiry
Does not expire while the connection remains active.
Revocation
Revoked when the seller disconnects the account, or by an administrator if the connection is found to be shared or fraudulent. One GitHub account can be connected to one seller account.

Company Domain Verified

The seller demonstrated control of the company domain shown on their profile by publishing a single-use verification token in the domain's DNS records.

What it does not mean

  • It does not confirm the legal status of the company.
  • It does not confirm the company's financial condition or trading history.
  • It does not verify the company's registration unless a separate business-verification process explicitly says so.
How it is earned
The seller adds a DNS TXT record containing a token esdecode generates for them. Free email and consumer hosting domains are not accepted as company domains.
Expiry
Subject to periodic re-verification; the DNS record must stay in place.
Revocation
Revoked when the DNS record is removed at re-verification, when the domain changes hands, or by an administrator.

Automated Security Scan Passed

The exact uploaded archive for this product version completed the automated checks that were enabled at scan time without unresolved blocking findings. The result is bound to the archive's SHA-256 hash, so it never carries over to a different upload.

What it does not mean

  • A passed automated scan does not guarantee the software is free from all vulnerabilities.
  • It does not prove the absence of malicious behaviour, configuration risks, or business-logic defects.
  • It applies only to the scanned version — a later update requires a new scan.
How it is earned
Every uploaded archive is hashed and queued for automated inspection: archive integrity, malware scanning, secret detection, dependency vulnerability scanning, and static suspicious-code checks.
Expiry
Tied to one version. When the seller uploads a new archive, the badge does not transfer to it.
Revocation
Removed when a new blocking finding is discovered against an already-published version, or when the archive changes after scanning.

Verified Purchase

The reviewer purchased this product through esdecode and the order had not been fully refunded when the review was submitted.

What it does not mean

  • It does not mean esdecode agrees with the review.
  • It does not mean the reviewer installed or deployed the product.
  • It does not mean the review was checked for technical accuracy.
How it is earned
Applied automatically. Only buyers with a qualifying order can submit a review at all.
Expiry
Never — it records the state at the time the review was written.
Revocation
Not revoked by a later refund. A refund after the fact does not rewrite the history of the review; it only prevents new reviews from that order.

Founding Seller

The seller joined esdecode during the founding-seller programme and met the eligibility conditions published for it.

What it does not mean

  • It does not indicate product quality or code security.
  • It does not indicate sales volume or popularity.
  • It is not an endorsement by esdecode.
  • It does not by itself guarantee any fee arrangement — fees follow the current seller terms.
How it is earned
Granted to sellers who met the published eligibility conditions while the programme was open.
Expiry
Does not expire on its own.
Revocation
Revoked if the account stops meeting the programme's good-standing conditions.

Founding Seller programme

The programme is currently open. Sellers who meet all of the conditions below may be granted the badge after review.

Published conditions

  • Created a seller account before 2027-01-01
  • Published at least 1 approved product
  • Completed identity verification
  • Accepted the current seller terms
  • Maintained an account in good standing

The badge is revocable if an account stops meeting these conditions. It carries no fee arrangement of its own — seller fees are set by the current seller terms and the published fee schedule.

Automated checks reduce risk. They cannot prove that software is free from every vulnerability, and their results apply only to the exact product version that was scanned. Always review a product's stated requirements and deploy it the way you would deploy any third-party code.