أمان & Responsible Disclosure

كيف يحمي "CodePus" رمزك، وثائقك و فريقك

Our أمان posture

CodePus encrypts بيانات in transit مع TLS 1.3 and at rest مع AES-256. Tenant بيانات يكون isolated per organisation. We follow ال principle of least privilege لـ الكل internal access and rotate signing مفتاح quarterly.

  • TLS 1.3 مع HSTS لـ every عام endpoint
  • At-rest encryption (AES-256) لـ استخدام records, secrets and نموذج traces
  • OAuth 2.0 + PKCE + RFC 8628 تدفق رمز الجهاز للوصول إلى IDE
  • SSO (SAML 2.0 / OIDC) و SCIM 2.0 للخطط المؤسسية
  • Per-طلب signing of تحديث artefacts (sha256 + https-only)

الامتثال

We continuously align مع industry standards.

  • SOC 2 نوع II — تدقيق in تقدم
  • القانون الدولي للاتصالات والتحقيقات والتحقيقات والتحقيقات والتحقيقات
  • إصدار خريطة للسيطرة من طراز ISO/IEC 27001 ، والخطط الجريهي للشهادة المنشورة أدناه

تقرير vulnerability

نرحب بالتقارير من الباحثين. يرجى اتباع الإفصاح المسؤول: لا تكشف عن المشكلة علناً حتى يكون لدينا وقت معقول لإصلاحها (عادةً 90 يوماً).

  • service@codepus.ai
  • بصمة الأصابع: 4C5E 1F0B 9E1A 7D2A 3F4B 6C7D 8E9F 0A1B 2C3D 4E5F
  • في نطاق: codepus.ai، *.codepus.ai، التوزيع الثنائي IDE والمخزن مفتوح المصدر.
  • Out of scope: clickjacking on unauthenticated marketing صفحة, missing أمان headers without proven تأثير, automated scanner إخراج.
  • Bounties of $100–$10,000 USD يكونون awarded لـ in-scope, reproducible vulnerabilities at ال discretion of ال أمان فريق.

قاعة المشاهير

We publish researcher acknowledgements with consent after the issue is resolved. Email service@codepus.ai if you would like to be listed.