Skip to content

Security: codai-ro/.github

Security

SECURITY.md

Security Policy (codai-ro organisation default)

This policy applies to every repository in the codai-ro organisation that does not ship its own SECURITY.md.

Reporting a vulnerability

Please do not open public issues for security vulnerabilities.

Email security@codai.ro with:

  • which project (phone, desktop, protocol, SDK) and version;
  • a description and reproduction steps;
  • a proof of concept if you have one.

Redact API keys, share tokens and push tokens from anything you send.

  • Acknowledgement within 72 hours.
  • Triage and severity within 7 days.
  • Fix or mitigation target: 30 days (critical), 90 days (everything else).

Coordinated disclosure

We follow a 90-day disclosure window from the acknowledgement date. You may publish after a fix ships or after 90 days, whichever comes first. We credit reporters in release notes unless you prefer otherwise.

Scope

Everything under codai-ro, and the live services they talk to — the gateway at ai.codai.ro, the console at codai.ro, authentication and billing — even though those services are not open source. Report them to the same address.

Out of scope: vulnerabilities in third-party apps that the phone agent drives on a user's device, and issues that require a rooted device or a compromised account to exploit.

Supported versions

The latest release of each project. Older releases receive fixes only when the fix is trivial to backport.

There aren't any published security advisories