ความปลอดภัย & Responsible Disclosure

วิธีที่ CodePus ป้องกันโค้ดของคุณ คุณสมบัติของคุณและทีมของคุณ

Our ความปลอดภัย posture

CodePus encrypts ข้อมูล in transit ด้วย TLS 1.3 and at rest ด้วย AES-256. Tenant ข้อมูล คือ isolated per organisation. We follow principle of least privilege สำหรับ ทั้งหมด internal access and rotate signing คีย์ quarterly.

  • TLS 1.3 ด้วย HSTS สำหรับ every สาธารณะ endpoint
  • At-rest encryption (AES-256) สำหรับ การใช้งาน records, secrets and โมเดล traces
  • OAuth 2.0 + PKCE + RFC 8628 การกระจายรหัสอุปกรณ์สําหรับ IDE เข้าระบบ
  • SSO (SAML 2.0 / OIDC) และ SCIM 2.0 สําหรับแผนการองค์กร
  • Per-คำขอ signing of อัปเดต artefacts (sha256 + https-only)

การปฏิบัติตาม

We continuously align ด้วย industry standards.

  • SOC 2 ประเภท II — ตรวจสอบ in ความคืบหน้า
  • GDPR & PIPL จุดปลายส่งและลบข้อมูลที่เปิดเผยใน /ดัชบอร์ด/ความปลอดภัย
  • ISO/IEC 27001 การควบคุมที่ถูกแผนที่ แผนการทําการรับรองที่เผยแพร่ลงด้านล่าง

รายงาน หนึ่ง vulnerability

เราต้อนรับรายงานจากนักวิจัยโปรดปฏิบัติตามการเปิดเผยอย่างมีหน้าที่ อย่าเปิดเผยปัญหาให้ประชาชน จนกว่าเราจะมีเวลาที่สมเหตุสมผลในการแก้ไขมัน (โดยทั่วไป 90 วัน)

  • service@codepus.ai
  • ปริ้นนิ้วมือ PGP: 4C5E 1F0B 9E1A 7D2A 3F4B 6C7D 8E9F 0A1B 2C3D 4E5F
  • ใน phạm vi: codepus.ai, *.codepus.ai, IDE การจําหน่ายไบนารี่และสํานักเก็บข้อมูลแหล่งเปิด
  • Out of scope: clickjacking on unauthenticated marketing หน้า, missing ความปลอดภัย headers without proven ผลกระทบ, automated scanner เอาต์พุต.
  • Bounties of $100–$10,000 USD เป็น awarded สำหรับ in-scope, reproducible vulnerabilities at discretion of ความปลอดภัย ทีม.

ห้องชมเชิงปุ๋ย

We publish researcher acknowledgements with consent after the issue is resolved. Email service@codepus.ai if you would like to be listed.