Security at Code Index
At Code Index, safeguarding your data and ensuring the integrity of our platform is a top priority. We employ a range of security measures to protect the Service and its users.
Data Encryption
All data is encrypted both in transit and at rest using industry-standard protocols. Communication between your browser and our servers is secured via HTTPS using TLS 1.2 or higher.
Access Controls
We implement strict access controls across our infrastructure and application stack:
- Principle of least privilege enforced for all internal systems
- Role-based access and audit trails for internal usage
- Internal services run in isolated, firewalled environments
Audit Logging
All access and key operations are logged and monitored to ensure visibility and enable rapid response to any suspicious activity.
Penetration Testing
We regularly undergo third-party penetration tests to evaluate the security of our systems and proactively remediate vulnerabilities.
Vulnerability Reporting
Security researchers and users are encouraged to report potential vulnerabilities through our GitHub Security page. We take all reports seriously and aim to respond promptly.
GDPR and Data Privacy
We are committed to user privacy and data protection. Users may request data deletion, and all collected data is handled in accordance with applicable privacy laws, including GDPR.
Agent Activity and Prompt Data
For transparency and accountability, developer agent interactions (such as queries and prompt history) may be logged solely for debugging, performance analysis, and improving user experience.
Responsible Disclosure
We value the security community. If you believe you've found a security vulnerability in our Service, please report it responsibly. Do not attempt to access or modify data without permission. Submit reports confidentially through our GitHub Security page. We aim to acknowledge receipt of vulnerability reports within 2 business days.
Contact Us
If you have security-related questions or concerns, please contact us at security@cidx.dev.
Security is an ongoing effort. As we evolve the Code Index platform, we will continue to invest in robust security practices and technologies to protect our users and their data.