Honest Cheetah for Azure DevOps: Privacy & Security
Last updated 2026-09-13. Covers the free extension from the Visual Studio Marketplace.
The short version
Your data stays in Azure DevOps. The extension runs inside your Azure DevOps organization and sends nothing to Honest Cheetah or to anyone else.
How it works
Honest Cheetah for Azure DevOps installs from the Visual Studio Marketplace and becomes part of your Azure DevOps organization, like any other extension. Once installed, it runs entirely inside your Azure DevOps environment, in your browser, against your organization's own APIs.
It reads work item data through the Azure DevOps OData Analytics API and the Work API, using two read-only scopes:
vso.work: read access to work items and backlogsvso.analytics: read access to analytics data
No data is sent to Honest Cheetah servers or to any third party. Ordinary browser caching applies, as it does to any web page.
Authentication and access control
Honest Cheetah creates no accounts, stores no passwords, and handles no authentication of its own. It relies entirely on Azure DevOps and Microsoft Entra ID:
- You sign in with the credentials you already have.
- Your organization's multi-factor authentication policies apply automatically.
- Azure DevOps' role-based access controls are respected in full. You see only what you were already authorized to see.
- The extension does not extend, override, or bypass any access control.
Encryption
All communication between the extension and Azure DevOps uses HTTPS with TLS 1.2 or better, enforced by Microsoft's infrastructure. Since no data leaves Azure DevOps, there is no additional encryption layer to manage.
External content
The extension's interface links to short documentation and tutorial videos on YouTube. Following one of those links takes you to YouTube, which is subject to Google's privacy policy. No data from your Azure DevOps environment goes with you.
What it doesn't do
- It doesn't store your work item data on our servers.
- It doesn't transfer data outside Azure DevOps.
- It doesn't create separate user accounts or passwords.
- It doesn't access financial, HR, or any data other than work items.
- It doesn't integrate with any third-party service beyond Azure DevOps.
- It doesn't collect telemetry or usage analytics from your Azure DevOps environment.
Data residency and compliance
Because your data never leaves Azure DevOps, data residency is determined entirely by where Microsoft hosts your Azure DevOps organization. The extension introduces no additional GDPR, HIPAA, or other regulatory obligations.
Auditing
Azure DevOps provides built-in audit logs covering authentication, access, and user activity. Since the extension operates inside Azure DevOps using standard APIs, all of its access is captured by Azure DevOps' native auditing.
Uninstalling
If you uninstall the extension from your Azure DevOps organization, there is nothing to delete or export from our side. We never had your data.
Questions
Privacy or security questions: support@honestcheetah.com.