Top secret types
By app category
By provider
Where secrets live (path archetype)
By storefront region
Secrets per app
Methodology & privacy
- Aggregate-only; every published number counts distinct apps and is k-anonymised (small buckets are merged/suppressed).
- No app identities, package names, secret values, or exact file paths are ever published.
- Storefront is where an app charts, not its origin. Counts are lower bounds.
- Affected developers are notified privately; this is not name-and-shame.