សុវត្ថិភាព & Responsible Disclosure
របៀប ដែល CodePus ការពារ កូដ របស់ អ្នក លក្ខណសម្បត្តិ និង ក្រុម របស់ អ្នក។
Our សុវត្ថិភាព posture
CodePus encrypts ទិន្នន័យ in transit ជាមួយ TLS 1.3 and at rest ជាមួយ AES-256. Tenant ទិន្នន័យ គឺ isolated per organisation. We follow principle of least privilege សម្រាប់ ទាំងអស់ internal access and rotate signing សោ quarterly.
- TLS 1.3 ជាមួយ HSTS សម្រាប់ every សាធារណៈ endpoint
- At-rest encryption (AES-256) សម្រាប់ ការប្រើប្រាស់ records, secrets and ម៉ូដែល traces
- OAuth 2.0 + PKCE + RFC 8628 ការផ្គត់ផ្គង់កូដឧបករណ៍សម្រាប់ IDE login
- SSO (SAML 2.0 / OIDC) និង SCIM 2.0 សម្រាប់ផែនការ Enterprise
- Per-សំណើ signing of ធ្វើបច្ចុប្បន្នភាព artefacts (sha256 + https-only)
ការ អនុវត្ត
We continuously align ជាមួយ industry standards.
- SOC 2 ប្រភេទ II — សវនកម្ម in វឌ្ឍនភាព
- GDPR & PIPL បញ្ចប់ការនាំចេញ និងលុបទិន្នន័យដែលត្រូវបានបង្ហាញនៅក្នុង /dashboard/security
- ISO/IEC 27001 ការគ្រប់គ្រងត្រូវបានរៀបចំឡើង, ផែនទីផ្លូវការនៃការបញ្ជាក់ត្រូវបានផ្សាយខាងក្រោម
របាយការណ៍ មួយ vulnerability
យើង ស្វាគមន៍ ការ រាយការណ៍ ពី អ្នកស្រាវជ្រាវ សូម អនុវត្ត ការ ផ្សព្វផ្សាយ ដោយ ប្រកប ដោយ ប្រសិទ្ធភាព: កុំ ឲ្យ ផ្សព្វផ្សាយ ជា សាធារណៈ បញ្ហា នេះ រហូត ដល់ យើង មាន ពេល សមរម្យ ដើម្បី ដោះស្រាយ វា (ជាទូទៅ ៩០ ថ្ងៃ) ។
- service@codepus.ai
ការធ្វើតេស្តអក្សរ PGP: 4C5E 1F0B 9E1A 7D2A 3F4B 6C7D 8E9F 0A1B 2C3D 4E5F- ក្នុង បរិមាណ: codepus.ai, *.codepus.ai, ការចែកចាយប៊ីណារី IDE និងគំរូឯកសារបើកបរ។
- Out of scope: clickjacking on unauthenticated marketing ទំព័រ, missing សុវត្ថិភាព headers without proven ផលប៉ះពាល់, automated scanner លទ្ធផល.
- Bounties of $100–$10,000 USD ជា awarded សម្រាប់ in-scope, reproducible vulnerabilities at discretion of សុវត្ថិភាព ក្រុម.
សាលា រាជវង្ស សត្វល្អិត
We publish researcher acknowledgements with consent after the issue is resolved. Email service@codepus.ai if you would like to be listed.