Security

Last updated: 4 August 2026

Coderex runs terminals on your own computer and lets you reach them from a browser somewhere else. Most of what needs protecting therefore never leaves your machine. This page explains how the parts that do travel are built, how to report a vulnerability, and what we promise researchers who find one.

Reporting a vulnerability

Email security@coderex.com. Please include what an attacker could achieve, which component is affected, and enough detail to reproduce it. Redact any real credentials or personal data from your evidence.

We aim to acknowledge a complete report within two business days, tell you whether we consider it a vulnerability, and keep you updated until it is closed. We will credit you when we ship the fix if you would like us to. We do not currently run a paid bug bounty, and we would rather say so plainly than imply one.

Safe harbour

If you research in good faith under the rules below, we will not pursue legal action against you, and we will say so if a third party asks. Stay within your own account and devices, stop as soon as you have proof, and give us reasonable time to fix an issue before publishing it.

Out of scope

Some behaviour looks alarming and is exactly what the product is for:

How Coderex is built

What we need from you

Changes

We update this page as the product changes. See also our Privacy Policy for what we store, and our Terms for the rules that govern use of the service.