This policy applies to every repository in the codai-ro
organisation that does not ship its own SECURITY.md.
Please do not open public issues for security vulnerabilities.
Email security@codai.ro with:
- which project (phone, desktop, protocol, SDK) and version;
- a description and reproduction steps;
- a proof of concept if you have one.
Redact API keys, share tokens and push tokens from anything you send.
- Acknowledgement within 72 hours.
- Triage and severity within 7 days.
- Fix or mitigation target: 30 days (critical), 90 days (everything else).
We follow a 90-day disclosure window from the acknowledgement date. You may publish after a fix ships or after 90 days, whichever comes first. We credit reporters in release notes unless you prefer otherwise.
Everything under codai-ro, and the live services they talk to — the gateway
at ai.codai.ro, the console at codai.ro, authentication and billing — even
though those services are not open source. Report them to the same address.
Out of scope: vulnerabilities in third-party apps that the phone agent drives on a user's device, and issues that require a rooted device or a compromised account to exploit.
The latest release of each project. Older releases receive fixes only when the fix is trivial to backport.