Security policy
Reporting a vulnerability
Email security@motorbay.app. Please don't open a public issue.
Include what you found, how to reproduce it, and what an attacker could do with it. If you've accessed data that isn't yours, stop there and tell us what you saw.
What happens next:
- We acknowledge your report within 2 working days.
- We fix or mitigate critical issues within 7 days, and tell you when it's done.
- We credit you when the fix is published, if you'd like to be named.
Scope
- Motorbay Console (
app.motorbay.app) - The Motorbay API (
api.motorbay.app) and the auth API (auth.motorbay.app)
Out of scope: denial-of-service testing, social engineering, physical attacks, and reports that only come from automated scanners without a demonstrated impact.
Safe harbor
We won't pursue or support legal action against research done in good faith within this policy: don't degrade the service, don't access or change other people's data beyond what you need to show the issue, and give us reasonable time to fix it before disclosing.
Copyright and takedown requests
If you believe something on Motorbay infringes your copyright or other rights, email support@motorbay.app with:
- the URL of the content on Motorbay, and what it infringes;
- your name and how to reach you;
- a statement that you own the rights or act for the owner, and that the notice is accurate.
We reply within 2 working days and remove content that infringes. The vehicle data comes from Motorstyrelsen's public register and is reused with their approval.
Machine-readable contact details are in /.well-known/security.txt.