Report vulnerabilities through GitHub private vulnerability reporting or email contact@magrathean.uk with subject SECURITY: Codexex.
Do not publish credentials, private keys, database dumps, signing certificates, or exploit details.
Include affected version/commit, platform, topology, reproduction steps, impact, and redacted evidence.
Magrathean UK Ltd. will not pursue a good-faith researcher for security disclosures that:
- Target non-production test systems or researcher-owned environments;
- Avoid persistence, destructive changes, denial of service, and access to personal or customer data;
- Report promptly and permit reasonable time for remediation;
- Do not condition non-disclosure on financial compensation.
No safe harbour covers phishing, credential stuffing, accessing private production infrastructure, large-scale scanning, denial of service, or unlawful conduct.