Ààbò & Responsible Disclosure
Bí CodePus ṣe ń dáàbò bo kọ́ọ̀dì rẹ, àwọn ìwé CodePus rẹ àti ẹgbẹ rẹ.
Our Ààbò posture
CodePus encrypts dátà in transit pẹ̀lú TLS 1.3 and at rest pẹ̀lú AES-256. Tenant dátà ni isolated per organisation. We follow principle of least privilege fún Gbogbo internal access and rotate signing Kọ́kọ́rọ́ quarterly.
- TLS 1.3 pẹ̀lú HSTS fún every gbogbo ènìyàn endpoint
- At-rest encryption (AES-256) fún Ìlò records, secrets and Àwoṣe traces
- OAuth 2.0 + PKCE + RFC 8628 ṣiṣan koodu ẹrọ fun IDE wọle
- SSO (SAML 2.0 / OIDC) ati SCIM 2.0 fun awọn eto Ile-iṣẹ
- Per-Ìbéèrè signing of Ìmúdójúìwọ̀n artefacts (sha256 + https-only)
Ìmúṣẹ
We continuously align pẹ̀lú industry standards.
- SOC 2 Irú II — ìṣayẹ̀wò in ìlọsíwájú
- GDPR & PIPL àwọn ìsọfúnni tó ń jáde àti ìsọfúnni tó ń pa run tí a ti fi hàn nínú /dashboard/security
- ISO/IEC 27001 àwọn ìtọ́jú tí a gbé àwòrán jáde, ìwé ìtọ́jú ìtọ́jú ìtọ́jú tí a tẹ̀ jáde nísàlẹ̀
Ìròyìn ọ̀kan vulnerability
A máa ń kí ìròyìn látọ̀dọ̀ àwọn olùṣèwádìí. Ẹ jọ̀wọ́ tẹ̀ lé ìfihàn tó yẹ: ẹ má ṣe sọ ìṣòro náà di mímọ̀ títí tá a bá ti ní àkókò tó tó láti yanjú rẹ̀ (ní ààlà 90 ọjọ́).
- service@codepus.ai
Àmì ọ̀pá ẹ̀rí PGP: 4C5E 1F0B 9E1A 7D2A 3F4B 6C7D 8E9F 0A1B 2C3D 4E5F- Nínú àyè: codepus.ai, *.codepus. ai, ìsọfúnni tó ń pín kiri IDE àti ibi tí wọ́n ti ń fi ìwé mímọ́ sílẹ̀ sí ṣii.
- Out of scope: clickjacking on unauthenticated marketing ojú-ìwé, missing Ààbò headers without proven ìkólù, automated scanner Ìjáde.
- Bounties of $100–$10,000 USD ni awarded fún in-scope, reproducible vulnerabilities at discretion of Ààbò Ẹgbẹ́.
Àwùjọ àwọn ẹ̀yẹ ìyìn fún àwọn kòkòrò
We publish researcher acknowledgements with consent after the issue is resolved. Email service@codepus.ai if you would like to be listed.