Vercel Security & compliance Releases Code quality Stability

Account supply chain

Integrations, owners, and domains on your Vercel team.

Overview

Reads team-level configuration rather than project code: which third-party integrations hold scopes, how many people hold owner rights, where your logs are being drained to, and whether your domains resolve the way Vercel expects.

What it looks for

  • Over-permissioned or team-wide integrations
  • Suspended or disabled integrations still holding their install grant
  • Non-marketplace integrations with multiple scopes
  • More owners than the team needs, and a backlog of pending invites
  • Log drains pointed at unrecognised third-party hosts
  • Domains unverified or reported by Vercel as misconfigured

Why it matters

A team-wide integration installed for one project reads all of them, and a suspended integration keeps its grant. Log drains are the quiet one — they carry request data continuously to whatever host was configured, however long ago.

Rules in this check

How the fixes arrive

GuideChanges only you can make safely arrive as a step-by-step guide you can follow yourself or hand to your coding agent.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.