mirror of
https://github.com/openai/codex.git
synced 2026-04-27 08:05:51 +00:00
Restore the `SECURITY.md` section from https://github.com/openai/codex/pull/17848. Note this was lost in the revert PR https://github.com/openai/codex/pull/18003.
18 lines
923 B
Markdown
18 lines
923 B
Markdown
# Security Policy
|
|
|
|
Thank you for helping us keep Codex secure!
|
|
|
|
## Reporting Security Issues
|
|
|
|
The security is essential to OpenAI's mission. We appreciate the work of security researchers acting in good faith to identify and responsibly report potential vulnerabilities, helping us maintain strong privacy and security standards for our users and technology.
|
|
|
|
Our security program is managed through Bugcrowd, and we ask that any validated vulnerabilities be reported via the [Bugcrowd program](https://bugcrowd.com/engagements/openai).
|
|
|
|
## Vulnerability Disclosure Program
|
|
|
|
Our Vulnerability Program Guidelines are defined on our [Bugcrowd program page](https://bugcrowd.com/engagements/openai).
|
|
|
|
## How to operate CODEX safely
|
|
|
|
For details on Codex security boundaries, including sandboxing, approvals, and network controls, see [Agent approvals & security](https://developers.openai.com/codex/agent-approvals-security).
|