பாதுகாப்பு & Responsible Disclosure

CodePus உங்கள் CodePus, உங்கள் சான்றிதழ்கள் மற்றும் உங்கள் குழுவை எவ்வாறு பாதுகாக்கிறது.

Our பாதுகாப்பு posture

CodePus encrypts தரவு in transit உடன் TLS 1.3 and at rest உடன் AES-256. Tenant தரவு ஆகும் isolated per organisation. We follow principle of least privilege க்காக அனைத்தும் internal access and rotate signing திறவு quarterly.

  • TLS 1.3 உடன் HSTS க்காக every பொது endpoint
  • At-rest encryption (AES-256) க்காக பயன்பாடு records, secrets and மாதிரி traces
  • IDE உள்நுழைவுக்கான OAuth 2.0 + PKCE + RFC 8628 சாதன குறியீடு ஓட்டம்
  • நிறுவன திட்டங்களுக்கான SSO (SAML 2.0 / OIDC) மற்றும் SCIM 2.0
  • Per-கோரிக்கை signing of புதுப்பிப்பு artefacts (sha256 + https-only)

இணக்கம்

We continuously align உடன் industry standards.

  • SOC 2 வகை II — தணிக்கை in முன்னேற்றம்
  • GDPR & PIPL /dashboard/security என்ற பகுதியில் வெளிப்படுத்தப்பட்ட தரவு ஏற்றுமதி மற்றும் நீக்குதல் முடிவுகள்
  • ISO/IEC 27001 கட்டுப்பாடுகள் வரைபடப்படுத்தப்பட்டன, சான்றிதழ் சான்றிதழ் வரைபடம் கீழே வெளியிடப்பட்டது

அறிக்கை ஒரு vulnerability

ஆராய்ச்சியாளர்களின் அறிக்கைகளை நாங்கள் வரவேற்கிறோம். தயவுசெய்து பொறுப்பான வெளிப்படுத்தலை பின்பற்றுங்கள்ஃ சிக்கலை சரிசெய்ய எங்களுக்கு நியாயமான நேரம் (பொதுவாக 90 நாட்கள்) இருக்கும் வரை அதை பகிரங்கமாக வெளியிட வேண்டாம்.

  • service@codepus.ai
  • PGP கைரேகைஃ 4C5E 1F0B 9E1A 7D2A 3F4B 6C7D 8E9F 0A1B 2C3D 4E5F
  • விவரக்குறிப்புஃ codepus.ai, *.codepus.ai, IDE இரட்டை விநியோகம் மற்றும் திறந்த மூல சேமிப்பு.
  • Out of scope: clickjacking on unauthenticated marketing பக்கம், missing பாதுகாப்பு headers without proven தாக்கம், automated scanner வெளியீடு.
  • Bounties of $100–$10,000 USD உள்ளன awarded க்காக in-scope, reproducible vulnerabilities at discretion of பாதுகாப்பு குழு.

பூச்சிகள் பரிசுகள் மண்டபம்

We publish researcher acknowledgements with consent after the issue is resolved. Email service@codepus.ai if you would like to be listed.