Ààbò & Responsible Disclosure

Bí CodePus ṣe ń dáàbò bo kọ́ọ̀dì rẹ, àwọn ìwé CodePus rẹ àti ẹgbẹ rẹ.

Our Ààbò posture

CodePus encrypts dátà in transit pẹ̀lú TLS 1.3 and at rest pẹ̀lú AES-256. Tenant dátà ni isolated per organisation. We follow principle of least privilege fún Gbogbo internal access and rotate signing Kọ́kọ́rọ́ quarterly.

  • TLS 1.3 pẹ̀lú HSTS fún every gbogbo ènìyàn endpoint
  • At-rest encryption (AES-256) fún Ìlò records, secrets and Àwoṣe traces
  • OAuth 2.0 + PKCE + RFC 8628 ṣiṣan koodu ẹrọ fun IDE wọle
  • SSO (SAML 2.0 / OIDC) ati SCIM 2.0 fun awọn eto Ile-iṣẹ
  • Per-Ìbéèrè signing of Ìmúdójúìwọ̀n artefacts (sha256 + https-only)

Ìmúṣẹ

We continuously align pẹ̀lú industry standards.

  • SOC 2 Irú II — ìṣayẹ̀wò in ìlọsíwájú
  • GDPR & PIPL àwọn ìsọfúnni tó ń jáde àti ìsọfúnni tó ń pa run tí a ti fi hàn nínú /dashboard/security
  • ISO/IEC 27001 àwọn ìtọ́jú tí a gbé àwòrán jáde, ìwé ìtọ́jú ìtọ́jú ìtọ́jú tí a tẹ̀ jáde nísàlẹ̀

Ìròyìn ọ̀kan vulnerability

A máa ń kí ìròyìn látọ̀dọ̀ àwọn olùṣèwádìí. Ẹ jọ̀wọ́ tẹ̀ lé ìfihàn tó yẹ: ẹ má ṣe sọ ìṣòro náà di mímọ̀ títí tá a bá ti ní àkókò tó tó láti yanjú rẹ̀ (ní ààlà 90 ọjọ́).

  • service@codepus.ai
  • Àmì ọ̀pá ẹ̀rí PGP: 4C5E 1F0B 9E1A 7D2A 3F4B 6C7D 8E9F 0A1B 2C3D 4E5F
  • Nínú àyè: codepus.ai, *.codepus. ai, ìsọfúnni tó ń pín kiri IDE àti ibi tí wọ́n ti ń fi ìwé mímọ́ sílẹ̀ sí ṣii.
  • Out of scope: clickjacking on unauthenticated marketing ojú-ìwé, missing Ààbò headers without proven ìkólù, automated scanner Ìjáde.
  • Bounties of $100–$10,000 USD ni awarded fún in-scope, reproducible vulnerabilities at discretion of Ààbò Ẹgbẹ́.

Àwùjọ àwọn ẹ̀yẹ ìyìn fún àwọn kòkòrò

We publish researcher acknowledgements with consent after the issue is resolved. Email service@codepus.ai if you would like to be listed.