أمان & Responsible Disclosure
كيف يحمي "CodePus" رمزك، وثائقك و فريقك
Our أمان posture
CodePus encrypts بيانات in transit مع TLS 1.3 and at rest مع AES-256. Tenant بيانات يكون isolated per organisation. We follow ال principle of least privilege لـ الكل internal access and rotate signing مفتاح quarterly.
- TLS 1.3 مع HSTS لـ every عام endpoint
- At-rest encryption (AES-256) لـ استخدام records, secrets and نموذج traces
- OAuth 2.0 + PKCE + RFC 8628 تدفق رمز الجهاز للوصول إلى IDE
- SSO (SAML 2.0 / OIDC) و SCIM 2.0 للخطط المؤسسية
- Per-طلب signing of تحديث artefacts (sha256 + https-only)
الامتثال
We continuously align مع industry standards.
- SOC 2 نوع II — تدقيق in تقدم
- القانون الدولي للاتصالات والتحقيقات والتحقيقات والتحقيقات والتحقيقات
- إصدار خريطة للسيطرة من طراز ISO/IEC 27001 ، والخطط الجريهي للشهادة المنشورة أدناه
تقرير vulnerability
نرحب بالتقارير من الباحثين. يرجى اتباع الإفصاح المسؤول: لا تكشف عن المشكلة علناً حتى يكون لدينا وقت معقول لإصلاحها (عادةً 90 يوماً).
- service@codepus.ai
بصمة الأصابع: 4C5E 1F0B 9E1A 7D2A 3F4B 6C7D 8E9F 0A1B 2C3D 4E5F- في نطاق: codepus.ai، *.codepus.ai، التوزيع الثنائي IDE والمخزن مفتوح المصدر.
- Out of scope: clickjacking on unauthenticated marketing صفحة, missing أمان headers without proven تأثير, automated scanner إخراج.
- Bounties of $100–$10,000 USD يكونون awarded لـ in-scope, reproducible vulnerabilities at ال discretion of ال أمان فريق.
قاعة المشاهير
We publish researcher acknowledgements with consent after the issue is resolved. Email service@codepus.ai if you would like to be listed.