Skip to content

Security: magrathean-uk/Codexex

SECURITY.md

Security Policy — Codexex

Private Reporting

Report vulnerabilities through GitHub private vulnerability reporting or email contact@magrathean.uk with subject SECURITY: Codexex.

Do not publish credentials, private keys, database dumps, signing certificates, or exploit details.

Include affected version/commit, platform, topology, reproduction steps, impact, and redacted evidence.

Scope & Safe Harbour

Magrathean UK Ltd. will not pursue a good-faith researcher for security disclosures that:

  • Target non-production test systems or researcher-owned environments;
  • Avoid persistence, destructive changes, denial of service, and access to personal or customer data;
  • Report promptly and permit reasonable time for remediation;
  • Do not condition non-disclosure on financial compensation.

Excluded Conduct

No safe harbour covers phishing, credential stuffing, accessing private production infrastructure, large-scale scanning, denial of service, or unlawful conduct.

There aren't any published security advisories