Seguridad & Responsible Disclosure

Paano pinapanahimikan ng CodePus ang iyong code, iyong mga credential at ang iyong koponan.

Our Seguridad posture

CodePus encrypts datos in transit sa TLS 1.3 and at rest sa AES-256. Tenant datos ay isolated per organisation. We follow ang principle of least privilege para Lahat internal access and rotate signing Susi quarterly.

  • TLS 1.3 sa HSTS para every pampubliko endpoint
  • At-rest encryption (AES-256) para Paggamit records, secrets and Modelo traces
  • OAuth 2.0 + PKCE + RFC 8628 pag-agos ng device-code para sa IDE login
  • SSO (SAML 2.0 / OIDC) at SCIM 2.0 para sa mga plano ng Enterprise
  • Per-Hiling signing of Update artefacts (sha256 + https-only)

Pagsusunod

We continuously align sa industry standards.

  • SOC 2 Uri II — pahina-audit in pahina-unlad
  • GDPR & PIPL mga endpoint ng pag-export at pagtanggal ng data na naka-expose sa ilalim ng /dashboard/security
  • ISO/IEC 27001 controls mapped, certification roadmap published below

Ulat isang vulnerability

Sinasalamatan namin ang mga ulat ng mga mananaliksik.

  • service@codepus.ai
  • PGP fingerprint: 4C5E 1F0B 9E1A 7D2A 3F4B 6C7D 8E9F 0A1B 2C3D 4E5F
  • Sa saklaw: codepus.ai, *.codepus.ai, ang binary distribution ng IDE at ang open-source repository.
  • Out of scope: clickjacking on unauthenticated marketing pahina, missing Seguridad headers without proven epekto, automated scanner Output.
  • Bounties of $100–$10,000 USD ay awarded para in-scope, reproducible vulnerabilities at ang discretion of ang Seguridad Koponan.

Hall of fame ng bug bounty

We publish researcher acknowledgements with consent after the issue is resolved. Email service@codepus.ai if you would like to be listed.