# Security Policy Codepanion is a B2B product with read access to our customers' source code and production databases. We take vulnerability reports seriously and appreciate the work of security researchers who help keep our customers safe. ## Reporting a vulnerability Please report security issues privately to **security@codepanion.app**. Do **not** open a public GitHub issue, pull request, or discussion for a suspected vulnerability: that exposes it before it can be fixed. Helpful things to include in your report: - A description of the issue and the impact you believe it has. - Step-by-step instructions to reproduce it (a proof of concept, request/response pairs, or a short script). - The affected component, URL, or endpoint, and any relevant timestamps. - Whether you accessed, modified, or stored any data that was not your own. If you would like to encrypt your report, mention that in your first email and we will arrange a key exchange. ## What to expect - We aim to acknowledge new reports within **2 business days**. - We will keep you updated as we triage, confirm, and work on a fix, and we will let you know when the issue is resolved. - With your permission, we are happy to credit you once a fix has shipped. ## Safe harbor We will not pursue or support legal action against researchers who: - Make a good-faith effort to follow this policy. - Avoid privacy violations, data destruction, and any degradation or interruption of our service (no denial-of-service, spam, or social-engineering of our staff, customers, or vendors). - Only interact with accounts and data they own or have explicit permission to test, and do not access, modify, or retain another tenant's data. - Stop testing and report immediately if they encounter customer data, and do not copy, store, transfer, or disclose it. - Give us a reasonable amount of time to remediate before any public disclosure, and coordinate disclosure timing with us. Activity conducted consistently with this policy is considered authorized, and we will not bring a claim against you for it. If a third party initiates legal action against you for activity that complied with this policy, we will make this authorization known. This policy does not authorize action against systems operated by our service providers (for example, Microsoft Azure). Issues in those systems should be reported to the respective provider. ## Scope In scope: - `www.codepanion.app` (marketing site) - `app.codepanion.app` (customer application) - `hub.codepanion.app` (admin panel) - The APIs backing the above. Out of scope: - Findings that require physical access to a user's device. - Reports from automated scanners without a demonstrated, exploitable impact. - Best-practice suggestions with no concrete security impact (e.g. missing hardening headers on endpoints that handle no sensitive data, weak ciphers with no practical attack, "self" XSS). - Denial-of-service, volumetric, or rate-limit testing. - Social engineering of our staff, customers, or vendors. ## A note on data and AI Customer data is **never** used to train models. Our AI features run on Azure OpenAI, which is contractually committed to not using customer prompts or completions to train its models. See for our full trust and privacy summary, including the current subprocessor list.