Thank you for taking the time to help us keep Apply.Build and our customers secure. We run a multi-tenant PaaS based in Finland and welcome reports of any vulnerability you find in our platform, APIs, or infrastructure.
1 Scope
| In scope | Out of scope |
|---|---|
*.apply.build web apps & APIs | Third-party customer applications ({tenant_app}.apps.apply.build) |
| Control panel & billing portal | Denial-of-Service (volumetric) |
| Kubernetes / Kata isolation, eBPF network policy, WAF | Automated scans without prior authorisation |
| Public ingress endpoints and TLS configuration | Issues that require physical access or social-engineering of Codebite staff |
If you are unsure whether something is in scope, ask first at security@codebite.fi.
2 Guidelines for Responsible Research
- Do not exploit a vulnerability beyond the minimal proof needed.
- Do not access or destroy other customers' data.
- Do not run high-volume or destructive scans.
- Do keep evidence (headers, PoC) to help us reproduce.
- Do respect GDPR - redact personal data where possible.
3 How to report
- E-mail: security@codebite.fi
- Preferred format: clear text or Markdown; include steps, impact, and suggestions.
4 Our commitment
We aim to respond promptly, keep you informed while we work on a fix, and agree with you on any public advisory. We will not pursue legal action when research follows this policy.
5 Recognition
We don't run a paid bug bounty, but we're grateful for every report.
6 Legal Safe Harbour
Activities conducted in good faith and in compliance with this policy are considered authorised. If legal action is initiated by a third party, we will make clear to the authority that your actions were conducted pursuant to this policy.