Last updated 9 October 2026.
1. Two analysis boundaries
Code Security runs source analysis on customer machines and sends findings only when requested; authorised snippets are separately controlled. FDIE processes uploaded firmware within the chosen hosted or on-premises deployment, including supported sandboxed runtime work. Combining the website does not combine these data paths.
2. Controls and responsibility
The Information Security Addendum describes transport/storage protection, identity, permissions, input handling, audit, analysis integrity and recovery. The Product Schedules allocate hosted and customer-operated responsibilities. Read the profile for the product being purchased; neither a shared brand nor a shared identity provider establishes equivalent settings.
This edition describes the AWS hosting profile that Code Security and FDIE have run on since 5 October 2026. Existing signed orders and processing terms continue until validly changed. Confirm the profile for your organisation before relying on a location, retention period or recovery objective.
3. Sensitive inputs and integrations
Firmware, reports, findings metadata and optional code excerpts can contain confidential information or personal data. Limit recipients, protect exports and review configured mail, webhook, repository, identity and model providers. No credentials, raw firmware or source archive should be submitted through this marketing website.
4. Development and incident response
Magdox reviews changes, monitors dependencies and reported issues, and prioritises investigation and remediation according to impact. Customer notification commitments are in the DPA and security addendum. A stated control does not guarantee every defect has been eliminated or every release is independently assessed.
Our infrastructure logs, including firewall, access, network and system logs, are kept for 180 days, the period the CERT-In Directions of 28 April 2022 require. The protected cloud audit trail, each product's activity log and backups have their own periods, set out in the Privacy Policy and the Information Security Addendum. We report cyber security incidents to CERT-In within six hours of noticing them where those Directions require it.
5. Assurance
No ISO 27001 certification, SOC 2 attestation or product regulatory approval is claimed. FDIE framework evidence supports a customer's assessment; it is not certification. Recovery objectives are deployment-specific and must be distinguished from completed restore tests.
6. Report a vulnerability
Email security@magdox.io and follow the combined Vulnerability Disclosure Policy at /responsible-disclosure/. Its scope includes the Magdox website and authorised research on Code Security and FDIE, with explicit limits for third-party and customer-operated systems.
The programme offers recognition with permission, not a paid bounty. Qualifying confirmed reports earn Critical 4, High 3, Medium 2 or Low 1 Hall of Fame points; Informational reports earn 0 and are not eligible for the Hall of Fame. The disclosure policy governs uniqueness, coordinated handling and publication. Published response targets are best effort, not customer uptime SLAs.
7. Intelligence sources
Code Security uses an approved platform-built advisory bundle from NVD, OSV, EPSS and CISA KEV data; the CLI can use an older cached copy. FDIE uses its configured vulnerability and prioritisation feeds, looks up the names and versions of libraries it finds in the public OSV.dev database, and preserves available assessment context. Neither product promises real-time or complete intelligence. Use of the NVD API does not imply NVD endorsement or certification.
8. Security updates, supported versions and advisories
Hosted services. Magdox applies security updates to hosted Code Security and FDIE while the customer's subscription is active; customers install nothing.
Software customers run under an agreement (FDIE on-premises, or a self-hosted Code Security dashboard). Security updates are provided while the customer's subscription or support agreement is active, for the release Magdox currently supports under it, through the delivery channel agreed with the customer.
The magdox CLI and its public packages. Security fixes are released only in the latest version, and older releases are not supported, so keep the CLI up to date. Releases and their notes are published at https://github.com/Magdox/magdox-cli/releases and in the Release Notes at https://magdox.io/docs/release-notes/.
Advisories. When we fix a vulnerability in software that customers install, we publish an advisory: for the CLI as a GitHub security advisory at https://github.com/Magdox/magdox-cli/security/advisories, for the MCP server at https://github.com/Magdox/MCP/security/advisories, and for FDIE on-premises with the release that fixes it, through the agreed channel. Where a vulnerability in a released version warrants one, we request a CVE identifier through GitHub.