Security Policy

Last updated: 4/9/2026

1. Introduction

Codcel is committed to maintaining a secure environment for our users. We take security seriously and appreciate responsible disclosures that help us keep our systems safe.

1A. Language and Translation Disclaimer

Codcel may provide this Security Policy and related documentation in languages other than English for convenience. These translations may be generated or assisted by automated tools.

In the event of any inconsistency, conflict, or ambiguity between a translated version and the English version, the English version shall prevail and is the only authoritative version.

All official security guidance, reporting instructions, and responsible disclosure procedures must be interpreted based solely on the English-language version.

2. Reporting a Vulnerability

If you discover a security vulnerability in any Codcel service, please report it privately and responsibly by emailing:

security@codcel.io

Do not publicly disclose the issue on GitHub, social media, or issue trackers. We will investigate all reports promptly.

3. Coordinated Vulnerability Response

When a vulnerability is reported, we prioritize verifying the issue, developing a fix, and coordinating a responsible disclosure timeline with the reporter. If necessary, we may contact affected users or partners to assist in remediation.

4. Security Advisory Disclosures

Once a fix is available, Codcel may publish a security advisory summarizing the issue, impact, and remediation details. Advisories may be published through:

  • GitHub Security Advisories
  • Release notes on GitHub
  • Codcel website announcements (if needed)

We encourage users to stay up to date with Codcel releases and apply security updates promptly.

5. Contact

If you have security-related questions or need urgent assistance, contact us at:

security@codcel.io