Security

Responsible disclosure and supported-product security.

Security reports should have a clear path, predictable acknowledgement, and responsible handling.

01

Report a vulnerability

Send a private report through the DevCodes contact channel with affected product/version, reproduction steps and impact. Do not publish exploit details before a fix window is agreed.

02

Supported versions

Security fixes target currently supported releases. Keep products updated before requesting compatibility help for older versions.

03

Security update process

Confirmed issues are triaged, patched, regression tested and documented in release notes with appropriate disclosure timing.

04

License integrity

License validation may protect hosted services and updates, but it must never delete customer files, content or databases.