Legal

Security

Reporting a vulnerability

If you believe you've found a security vulnerability in Autoview, we want to hear from you. Please report it privately rather than opening a public issue or posting about it before we've had a chance to respond.

Email security@autoview.com with a description of the issue, the steps to reproduce it, and its potential impact. We'll acknowledge your report and follow up as we investigate.

Our full policy is also published machine-readable at /.well-known/security.txt, per RFC 9116.

Safe harbor

We consider security research conducted under this policy to be authorized. We will not pursue legal action against, or refer to law enforcement, anyone who makes a good-faith effort to comply with it. This includes avoiding privacy violations, service disruption, and destruction of data, and reporting findings to us before disclosing them to anyone else.

In scope

Out of scope

These hosts and services are either redirect-only entry points into the same worker above, or third-party services we don't operate. Please report issues with them directly to their own owner, not to us.

Hall of fame

We're grateful to the researchers who've reported issues responsibly. See our hallway.txt for the list.