אבטחה & Responsible Disclosure

איך CodePus מגן על הקוד שלך, על תעודות האשראי שלך והצוות שלך.

Our אבטחה posture

CodePus encrypts נתונים in transit עם TLS 1.3 and at rest עם AES-256. Tenant נתונים הוא isolated per organisation. We follow ה principle of least privilege עבור הכל internal access and rotate signing מפתח quarterly.

  • TLS 1.3 עם HSTS עבור every ציבורי endpoint
  • At-rest encryption (AES-256) עבור שימוש records, secrets and מודל traces
  • OAuth 2.0 + PKCE + RFC 8628 זרימת קוד המכשיר עבור כניסת IDE
  • SSO (SAML 2.0 / OIDC) ו- SCIM 2.0 לתוכניות ארגון
  • Per-בקשה signing of עדכון artefacts (sha256 + https-only)

אימות

We continuously align עם industry standards.

  • SOC 2 סוג II — ביקורת in התקדמות
  • GDPR & PIPL נקודות הסיום של ייצוא וחיסול נתונים חשופות תחת /דאשבורד/ביטחון
  • ISO/IEC 27001 בקרות מופיעות, מפת דרכים לאישור פורסמת למטה

דוח vulnerability

אנו מעריכים את הדו"חות של חוקרים. נא לעקוב אחר גילוי אחראי: אל תעשי את הבעיה פומבית עד שיהיה לנו זמן סביר לתקן אותה (בדרך כלל 90 ימים).

  • service@codepus.ai
  • טביעת אצבע של PGP: 4C5E 1F0B 9E1A 7D2A 3F4B 6C7D 8E9F 0A1B 2C3D 4E5F
  • בתחום: codepus.ai, *.codepus.ai, התזזוגת בינרית של IDE ומחסנת קוד פתוח.
  • Out of scope: clickjacking on unauthenticated marketing דף, missing אבטחה headers without proven השפעה, automated scanner פלט.
  • Bounties of $100–$10,000 USD הם awarded עבור in-scope, reproducible vulnerabilities at ה discretion of ה אבטחה צוות.

אולם ההשפעה של תוספת חרקים

We publish researcher acknowledgements with consent after the issue is resolved. Email service@codepus.ai if you would like to be listed.