Found something? Tell us.
Plain instructions for security researchers, and a plain statement of how we will treat you.
We would rather hear about a weakness from you than from an incident. If you have found something in our marketing site, the desktop app, or the platform endpoints you are licensed to use, this page tells you how to report it and what happens next.
How to report
Email security@codemonster.ai. Use the subject line Vulnerability report so it is routed correctly.
A PGP key will be published here and in security.txt at launch. Until then, send an initial email without exploit details and we will arrange an encrypted channel for the rest.
Scope
In scope
- This website, codemonster.ai, and its subdomains — excluding app URLs that belong to another customer’s account.
- The CodeMonster desktop app, once builds are available — request an invite, say you are reporting under this policy, and we will arrange a build.
- Platform endpoints you are licensed to use — the MCP server, the platform API, and the app URLs of your own account and environments.
Out of scope
- Accounts, tenants, apps, or data that are not yours. Test only against your own account and environments.
- Denial-of-service, volumetric, or resource-exhaustion testing of any kind.
- Social engineering, phishing, or physical attacks on our staff, customers, or providers.
- Third-party services and subprocessors we use — report those to the provider under their own policy.
- Findings that require a compromised device, browser extension, or a person’s credentials to reproduce.
- Reports from automated scanners without a demonstrated impact, missing best-practice headers with no exploit path, and version banners.
If you are unsure whether something is in scope, ask first at the same address. We will answer before you test.
What to include
- The affected surface and URL, endpoint, or app component.
- Steps to reproduce, from a clean start, with the account and environment you used.
- What you were able to do or see, and your assessment of impact.
- Any request or response captures, screenshots, or a proof-of-concept — minimal, and touching only your own data.
- How you would like to be contacted, and whether you want credit if we publish an acknowledgement.
What to expect from us
- Acknowledgement. We aim to acknowledge every report within two business days. That is a target we hold ourselves to, not a contractual service level.
- Triage. We reproduce the issue, assess impact, and tell you whether we agree it is a vulnerability and how we rate it.
- Fix. We keep you informed of progress at reasonable intervals and tell you when a fix has shipped.
- Disclosure. We ask you to hold public disclosure until a fix has shipped, or 90 days from your report, whichever comes first. If we need longer we will tell you why and agree a date with you before that window closes. We will not ask for indefinite silence.
What we ask of you: report promptly, do not access, modify, or retain data beyond what is needed to demonstrate the issue, do not degrade the service for other users, and give us a reasonable window to fix before going public.
Safe harbor
If you conduct security research in good faith, within the scope above and in line with this policy, we consider it authorized. We will not pursue or support legal action against you for that research, and we will not report it to law enforcement as a violation. If a third party brings action against you for activity conducted in accordance with this policy, we will make it known that your actions were authorized under it.
Good faith means: you avoid privacy violations, data destruction, and service disruption; you test only against accounts and data you own or are authorized to use; you stop and report as soon as you can demonstrate the issue; and you do not exploit a finding beyond that demonstration.
This statement does not authorize activity that would break the law elsewhere, and it does not bind third parties. If you have a question about whether an action is covered, ask before you take it.
Credit
We do not run a paid bounty program today. Whether we publish a public acknowledgements page is being decided; if you would like credit for a confirmed report, say so when you write, and we will confirm what we can offer before disclosure.
security.txt
This policy backs the machine-readable file at /.well-known/security.txt (RFC 9116), which lists the same contact, this policy, and an expiry date so you can tell whether it is current.