Not Codex is an independent project and is not affiliated with, sponsored by, or endorsed by OpenAI, T3 Tools Inc., or the T3 Code project. Codex is a product and brand of OpenAI.
Not Codex
GitHub
← All legal documents

Not Codex / Legal

Not Codex Security Policy

Security reports should be private, reproducible, and free of unrelated personal data or secrets.

Effective Date
2026-07-21
Last Updated
2026-07-21

On this page

  1. 01Scope
  2. 02Report a vulnerability
  3. 03Responsible research
  4. 04What to expect
  5. 05Using Not Codex safely
  6. 06Contact

01

Scope

This policy covers the source at https://github.com/MaTriXy/not-codex and the public Site at https://notcodex.bpro.dev. No public hosted application or Connect service is currently in scope. Vulnerabilities in a third-party provider should also be reported to that provider.

02

Report a vulnerability

Use GitHub private vulnerability reporting when available, or email security@notcodex.bpro.dev. Do not open a public issue for an undisclosed vulnerability.

Include the affected commit or version, impact, reproduction steps, and a minimal proof of concept. Remove access tokens, credentials, private repository content, and unrelated personal data.

03

Responsible research

Test only systems and data you own or are explicitly authorized to test. Avoid privacy violations, service disruption, persistence, destructive actions, social engineering, and access beyond what is needed to demonstrate the issue. Stop and report promptly if you encounter sensitive data.

04

What to expect

We will acknowledge complete reports as soon as practical, investigate in good faith, and share meaningful status changes when possible. Please allow a reasonable opportunity to remediate before public disclosure. This early project does not promise a response-time or bounty program.

05

Using Not Codex safely

Not Codex controls agents with filesystem and command access. Build from reviewed source, use recoverable repositories, keep credentials out of prompts and logs, choose the least-permissive runtime that works, and do not expose the local server to an untrusted network.

06

Contact

Security: security@notcodex.bpro.dev. Privacy: privacy@notcodex.bpro.dev. General support: support@notcodex.bpro.dev.

© 2026 MaTrixy · MIT licensed
GitHubBuildTermsPrivacySecurity
Not Codex is an independent project and is not affiliated with, sponsored by, or endorsed by OpenAI, T3 Tools Inc., or the T3 Code project. Codex is a product and brand of OpenAI.