Responsible Disclosure & Security Policy

Last updated 7 October 2026

Thank you for taking the time to help us keep Apply.Build and our customers secure. We run a multi-tenant PaaS based in Finland and welcome reports of any vulnerability you find in our platform, APIs, or infrastructure.

1 Scope

In scopeOut of scope
*.apply.build web apps & APIsThird-party customer applications ({tenant_app}.apps.apply.build)
Control panel & billing portalDenial-of-Service (volumetric)
Kubernetes / Kata isolation, eBPF network policy, WAFAutomated scans without prior authorisation
Public ingress endpoints and TLS configurationIssues that require physical access or social-engineering of Codebite staff

If you are unsure whether something is in scope, ask first at security@codebite.fi.

2 Guidelines for Responsible Research

  • Do not exploit a vulnerability beyond the minimal proof needed.
  • Do not access or destroy other customers' data.
  • Do not run high-volume or destructive scans.
  • Do keep evidence (headers, PoC) to help us reproduce.
  • Do respect GDPR - redact personal data where possible.

3 How to report

  • E-mail: security@codebite.fi
  • Preferred format: clear text or Markdown; include steps, impact, and suggestions.

4 Our commitment

We aim to respond promptly, keep you informed while we work on a fix, and agree with you on any public advisory. We will not pursue legal action when research follows this policy.

5 Recognition

We don't run a paid bug bounty, but we're grateful for every report.

Activities conducted in good faith and in compliance with this policy are considered authorised. If legal action is initiated by a third party, we will make clear to the authority that your actions were conducted pursuant to this policy.

© 2026 Codebite Oy