Effective Date: September 1, 2025
At AutoCents™, we take the security and integrity of our platform and customer data very seriously. We welcome reports of security vulnerabilities from security researchers, users, and the public, and we are committed to responding responsibly.
We work with security researchers to identify and fix vulnerabilities before they can be exploited by malicious actors.
We acknowledge reports within 24 hours and provide regular updates throughout the investigation and remediation process.
We recognize and appreciate contributions from researchers who help us improve our security posture.
Ready to Report a Vulnerability? Send your report to security@speedlimit.com with detailed information about the issue you've discovered.
If you believe you have discovered a security vulnerability in AutoCents that is in-scope (see below), please report it as soon as possible to our security team. To submit a report, send an email to:
security@speedlimit.com
Include the following in your report:
Vulnerabilities or issues in the following systems/components are in-scope:
CVSS Score Requirement:
Note: To qualify for acknowledgement or recognition, the reported vulnerability should have a CVSS base score of 4.0 or higher.
The following are not in scope (we may choose not to act on reports of these issues, though you may report them nonetheless):
When submitting a report, we ask that you:
Legal Protection for Researchers
AutoCents will not pursue legal action against anyone who, in good faith:
Important Note:
This safe harbor applies only to the extent permitted by applicable law. If you are uncertain whether your testing would violate this policy or local law, contact us first at security@speedlimit.com for clarity.
We aim to handle vulnerability reports as follows:
Stage | Target Timeframe |
---|---|
Acknowledgement of receipt | Within 24 hours of receiving your report |
Initial validation | Within 3 business days |
Regular status updates | At least every 7 days while issue is under investigation |
Resolution of critical/severe vulnerabilities | As quickly as possible, targeted within 30 calendar days (or sooner if feasible) |
Coordinated public disclosure | Once the issue is remediated, subject to mutual agreement (if applicable) |
Recognition Program
At this time, AutoCents does not offer financial bounties for vulnerability reports. However, we do recognize and appreciate contributions from researchers.
For qualifying reports (CVSS 4.0+), we may provide non-monetary acknowledgments such as:
We may update this Vulnerability Disclosure Policy periodically. When we do, we will:
We encourage security researchers to review this page from time to time to stay informed of any changes to our vulnerability disclosure process.
This policy is governed by the laws of the State of New Hampshire, United States. Any legal actions or disputes arising from this policy shall be subject to those laws.
Any disputes or legal matters related to this vulnerability disclosure policy will be resolved in the courts of New Hampshire, United States.
If you have questions or concerns about this policy, or about whether a vulnerability is in scope, you can reach out:
Response Time: We typically respond to security inquiries within 24 hours. For urgent security matters, please mark your email as "URGENT" in the subject line.