01
Scope
This policy covers the source at https://github.com/MaTriXy/not-codex and the public Site at https://notcodex.bpro.dev. No public hosted application or Connect service is currently in scope. Vulnerabilities in a third-party provider should also be reported to that provider.
02
Report a vulnerability
Use GitHub private vulnerability reporting when available, or email security@notcodex.bpro.dev. Do not open a public issue for an undisclosed vulnerability.
Include the affected commit or version, impact, reproduction steps, and a minimal proof of concept. Remove access tokens, credentials, private repository content, and unrelated personal data.
03
Responsible research
Test only systems and data you own or are explicitly authorized to test. Avoid privacy violations, service disruption, persistence, destructive actions, social engineering, and access beyond what is needed to demonstrate the issue. Stop and report promptly if you encounter sensitive data.
04
What to expect
We will acknowledge complete reports as soon as practical, investigate in good faith, and share meaningful status changes when possible. Please allow a reasonable opportunity to remediate before public disclosure. This early project does not promise a response-time or bounty program.
05
Using Not Codex safely
Not Codex controls agents with filesystem and command access. Build from reviewed source, use recoverable repositories, keep credentials out of prompts and logs, choose the least-permissive runtime that works, and do not expose the local server to an untrusted network.
06
Contact
Security: security@notcodex.bpro.dev. Privacy: privacy@notcodex.bpro.dev. General support: support@notcodex.bpro.dev.