Skip to content

Security: codai-ro/codai-phone

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not open public issues for security vulnerabilities.

Email [email protected] with a description, affected version (versionName from Settings → About or app/build.gradle.kts), reproduction steps and, if you have one, a proof of concept. Encrypt with the key published at https://codai.ro/.well-known/security.txt if the report is sensitive.

  • Acknowledgement within 72 hours.
  • Triage and severity within 7 days.
  • Fix or mitigation target: 30 days (critical), 90 days (everything else).

Coordinated disclosure

We follow a 90-day disclosure window from the acknowledgement date. You may publish after a fix ships or after 90 days, whichever comes first; we will credit you in the release notes unless you prefer otherwise. Please give us the chance to ship the fix before publishing details.

Scope

This repository is the Android client only. In scope:

  • Accessibility-service automation (tap/type/scroll of other apps) — any way to drive it without user consent or outside a running turn.
  • Storage of the codai_ API key / provider keys (EncryptedSharedPreferences).
  • The companion terminal bridge (:terminal, AIDL) and its PackageInstaller path.
  • Session sync / shared sessions (lease, control routing, viewer read-only enforcement).
  • Deep links, exported components, broadcast receivers (DebugDrive).

Out of scope here (report to the same address, but they live in other repos): the codai gateway, auth server, billing, and the model catalogue. Findings in third-party apps the agent drives are out of scope entirely.

Supported versions

Only the latest release on the main branch receives security fixes.

No secrets by design

The client holds no shared secrets. The OAuth client ids in local.defaults.properties are public identifiers by OAuth design and are not vulnerabilities. Never commit an API key — the app mints one per device at sign-in and revokes it at sign-out.

There aren't any published security advisories