សុវត្ថិភាព & Responsible Disclosure

របៀប ដែល CodePus ការពារ កូដ របស់ អ្នក លក្ខណសម្បត្តិ និង ក្រុម របស់ អ្នក។

Our សុវត្ថិភាព posture

CodePus encrypts ទិន្នន័យ in transit ជាមួយ TLS 1.3 and at rest ជាមួយ AES-256. Tenant ទិន្នន័យ គឺ isolated per organisation. We follow principle of least privilege សម្រាប់ ទាំងអស់ internal access and rotate signing សោ quarterly.

  • TLS 1.3 ជាមួយ HSTS សម្រាប់ every សាធារណៈ endpoint
  • At-rest encryption (AES-256) សម្រាប់ ការប្រើប្រាស់ records, secrets and ម៉ូដែល traces
  • OAuth 2.0 + PKCE + RFC 8628 ការផ្គត់ផ្គង់កូដឧបករណ៍សម្រាប់ IDE login
  • SSO (SAML 2.0 / OIDC) និង SCIM 2.0 សម្រាប់ផែនការ Enterprise
  • Per-សំណើ signing of ធ្វើបច្ចុប្បន្នភាព artefacts (sha256 + https-only)

ការ អនុវត្ត

We continuously align ជាមួយ industry standards.

  • SOC 2 ប្រភេទ II — សវនកម្ម in វឌ្ឍនភាព
  • GDPR & PIPL បញ្ចប់ការនាំចេញ និងលុបទិន្នន័យដែលត្រូវបានបង្ហាញនៅក្នុង /dashboard/security
  • ISO/IEC 27001 ការគ្រប់គ្រងត្រូវបានរៀបចំឡើង, ផែនទីផ្លូវការនៃការបញ្ជាក់ត្រូវបានផ្សាយខាងក្រោម

របាយការណ៍ មួយ vulnerability

យើង ស្វាគមន៍ ការ រាយការណ៍ ពី អ្នកស្រាវជ្រាវ សូម អនុវត្ត ការ ផ្សព្វផ្សាយ ដោយ ប្រកប ដោយ ប្រសិទ្ធភាព: កុំ ឲ្យ ផ្សព្វផ្សាយ ជា សាធារណៈ បញ្ហា នេះ រហូត ដល់ យើង មាន ពេល សមរម្យ ដើម្បី ដោះស្រាយ វា (ជាទូទៅ ៩០ ថ្ងៃ) ។

  • service@codepus.ai
  • ការធ្វើតេស្តអក្សរ PGP: 4C5E 1F0B 9E1A 7D2A 3F4B 6C7D 8E9F 0A1B 2C3D 4E5F
  • ក្នុង បរិមាណ: codepus.ai, *.codepus.ai, ការចែកចាយប៊ីណារី IDE និងគំរូឯកសារបើកបរ។
  • Out of scope: clickjacking on unauthenticated marketing ទំព័រ, missing សុវត្ថិភាព headers without proven ផលប៉ះពាល់, automated scanner លទ្ធផល.
  • Bounties of $100–$10,000 USD ជា awarded សម្រាប់ in-scope, reproducible vulnerabilities at discretion of សុវត្ថិភាព ក្រុម.

សាលា រាជវង្ស សត្វល្អិត

We publish researcher acknowledgements with consent after the issue is resolved. Email service@codepus.ai if you would like to be listed.