Usalama & Responsible Disclosure

Jinsi CodePus kulinda code yako, vitambulisho yako na timu yako.

Our Usalama posture

CodePus encrypts data in transit na TLS 1.3 and at rest na AES-256. Tenant data ni isolated per organisation. We follow principle of least privilege kwa Zote internal access and rotate signing Ufunguo quarterly.

  • TLS 1.3 na HSTS kwa every umma endpoint
  • At-rest encryption (AES-256) kwa Matumizi records, secrets and Mfano traces
  • OAuth 2.0 + PKCE + RFC 8628 kifaa-code mtiririko kwa IDE kuingia
  • SSO (SAML 2.0 / OIDC) na SCIM 2.0 kwa mipango ya Biashara
  • Per-Ombi signing of Sasisha artefacts (sha256 + https-only)

Kufuata

We continuously align na industry standards.

  • SOC 2 Aina II — ukaguzi in maendeleo
  • GDPR & PIPL data nje na kufuta mwisho pointi wazi chini ya /dashboard/ usalama
  • ISO/IEC 27001 udhibiti imechorwa, ramani ya barabara ya udhibitisho iliyochapishwa hapa chini

Ripoti moja vulnerability

Tunapokaribisha ripoti kutoka kwa watafiti, tafadhali fuata taarifa za uwazi: usitoe habari za wazi kuhusu tatizo hilo mpaka tuweze kupata muda wa kutosha ili kurekebisha tatizo hilo (kwa kawaida siku 90).

  • service@codepus.ai
  • PGP alama ya kidole: 4C5E 1F0B 9E1A 7D2A 3F4B 6C7D 8E9F 0A1B 2C3D 4E5F
  • Katika wigo: codepus.ai, *.codepus.ai, IDE usambazaji binary na hifadhi ya chanzo wazi.
  • Out of scope: clickjacking on unauthenticated marketing ukurasa, missing Usalama headers without proven athari, automated scanner Tokeo.
  • Bounties of $100–$10,000 USD ni awarded kwa in-scope, reproducible vulnerabilities at discretion of Usalama Timu.

Bug bounty hall ya umaarufu

We publish researcher acknowledgements with consent after the issue is resolved. Email service@codepus.ai if you would like to be listed.