安全性 & Responsible Disclosure

如何保護你的代碼,身份證和團隊? CodePus

Our 安全性 posture

CodePus encrypts 資料 進入 transit 與 TLS 1.3 and at rest 與 AES-256. Tenant 資料 是 isolated per organisation. We follow 這個 principle of least privilege 用於 全部 internal access and rotate signing 金鑰 quarterly.

  • TLS 1.3 與 HSTS 用於 每個 公開 endpoint
  • At-rest encryption (AES-256) 用於 用量 records, secrets and 模型 traces
  • 該系統的使用方式:
  • 企業計畫的SSO (SAML 2.0/OIDC) 和SCIM 2.0
  • Per-請求 signing of 更新 artefacts (sha256 + https-開啟)

合規

We continuously align 與 industry standards.

  • SOC 2 類型 II — 審計 進入 進度
  • GDPR和PIPL /dashboard/security下暴露的數據輸出和删除終點
  • ISO/IEC 27001—控制項已映射,認證路线圖下面公布

回報 一個 vulnerability

我們歡迎來自研究人員的報告. 請遵守責任的披露:我們在合理的時間內 (通常是90天) 解決問題之前,不要公開問題.

  • service@codepus.ai
  • 指紋: 4C5E 1F0B 9E1A 7D2A 3F4B 6C7D 8E9F 0A1B 2C3D 4E5F
  • 範圍: codepus.ai, *.codepus.ai,IDE二元分布和開放源庫.
  • 登出 of scope: clickjacking 開啟 unauthenticated marketing 頁面, missing 安全性 headers without proven 影響, automated scanner 輸出.
  • Bounties of $100–$10,000 USD 是 awarded 用於 進入-scope, reproducible vulnerabilities at 這個 discretion of 這個 安全性 團隊.

獎勵名人堂

We publish researcher acknowledgements with consent after the issue is resolved. Email service@codepus.ai if you would like to be listed.