TRUST · SECURITY
Security, built in by default.
How we protect your code — from the moment you press enter to the moment it’s discarded.
security-overview.md
read-only
soc 2
Type II · audited yearly
encryption
AES-256 · TLS 1.3
code retention
0 s by default
pen testing
Quarterly, third party
bug bounty
Up to $10,000
TL;DR
Security at a glance
§01
How your code flows
Every request follows the same short path. Nothing about your code is written to disk, logged or reused once your response is returned.
01
Your editor
CLI · IDE · API
02
In transit
TLS 1.3 · HSTS
03
Isolated worker
In-memory only
04
Diff returned
Signed · streamed
05
Discarded
0 s retention
// Enterprise workspaces can pin workers to the EU or run them inside their own VPC.
§02
Security controls
Security is part of how we build, not a layer on top. These controls apply to every plan.
§03
Compliance
We maintain independent attestations and contractual commitments so your security and procurement reviews move quickly.
§04
Sub-processors
These third parties process customer data on our behalf under written agreements. We give customers 30 days’ notice before adding a new sub-processor.
vendor
purpose
location
Cloud hosting and storage
US · EU
Network security and CDN
Global
Infrastructure monitoring
US · EU
Payment processing
US
Transactional email
US
Customer support
US
§05
Responsible disclosure
If you believe you’ve found a vulnerability, email security@codecraft.dev with the details. We acknowledge reports within 24 hours, keep you updated as we fix the issue and credit researchers who want recognition.
Please don’t access other customers’ data, run denial-of-service tests or use social engineering. Good-faith research that follows these rules is welcome and won’t lead to legal action.
/.well-known/security.txt
Contact: mailto:security@codecraft.dev
Encryption: codecraft.dev/pgp-key.txt
Policy: codecraft.dev/security
Acknowledgments: codecraft.dev/security#thanks
Preferred-Languages: en
Expires: 2027-09-01T00:00:00Z
BOUNTY REWARDS
Critical
up to $10,000
High
up to $4,000
Medium
up to $1,000
Low
Swag + credit
§06
Security updates
A running log of notable security milestones and changes.
2026.09
Sep 18, 2026
+ Completed Q3 third-party penetration test — no high-severity findings
+ Added hardware-key requirement for all production access
2026.07
Jul 2, 2026
+ Renewed SOC 2 Type II attestation
2026.04
Apr 9, 2026
+ EU data residency available on all paid plans
− Retired legacy API keys without scopes











