This is the organization-wide security policy for CocoIndex, Inc. It applies to all CocoIndex software and to cocoindex.io, and serves as the default policy for any repository in this organization without its own SECURITY.md.
Email security@cocoindex.io. Please do not open public issues for security reports.
- We acknowledge reports within 3 business days.
- We prefer coordinated disclosure: we'll work with you on a fix and agree on a disclosure timeline before details are published.
- There is currently no bug bounty program; we gladly credit reporters in the fix-release advisory unless you prefer otherwise.
| Product | Where | Product policy |
|---|---|---|
| CocoIndex (open-source framework) | cocoindex-io/cocoindex |
policy |
| CocoIndex Code (open source) | cocoindex-io/cocoindex-code |
policy |
| CocoIndex Code Plus + CocoIndex Plus engine (enterprise, self-hosted) | PyPI cocoindex-code-plus, GHCR images, Helm chart, licensed engine wheels |
policy |
| cocoindex.io (website) | this policy | — |
Machine-readable pointer: https://cocoindex.io/.well-known/security.txt (RFC 9116).