Vulnerability Disclosure Policy

1. Introduction

The security and integrity of our digital systems are of paramount importance. As part of our commitment to maintaining a secure environment, we welcome the assistance of security researchers and the broader community in identifying and responsibly disclosing vulnerabilities. This Vulnerability Disclosure Policy outlines the guidelines and procedures for reporting security vulnerabilities to us.

2. Scope

This policy covers all digital assets, services, applications, and systems owned or operated by Collect Car BV and its subsidiaries. This includes websites, web applications, mobile applications, APIs, and any other digital resources.

3. Goals

We encourage security researchers to report any discovered vulnerabilities in accordance with the following guidelines:
  • Vulnerabilities should be reported as soon as possible to our dedicated email address: security@greenwheels.com
  • Provide a detailed description of the vulnerability, including steps to reproduce it and any supporting materials.
  • Include your contact information for communication purposes (email or other preferred method).
  • Please allow us a reasonable amount of time to investigate and remediate the reported vulnerability before publicly disclosing any information.
  • We commit to acknowledging receipt of your report within three business days and will provide regular updates on the status of the remediation process.
  • We will treat all information provided as confidential and will not share any personal or sensitive information without your explicit consent, unless required by law.

4. Guidelines for researchers

When participating in responsible disclosure, we expect security researchers to adhere to the following principles:
  • Do not exploit or further compromise the vulnerability beyond what is necessary to demonstrate the issue.
  • Do not access, modify, or delete data that does not belong to you.
  • Do not disclose the vulnerability publicly before receiving explicit permission from us.
  • Respect the privacy and confidentiality of our users and systems throughout the disclosure process.
  • Engage in a professional and respectful manner when communicating with our team.

5. Our commitment

Upon receiving a vulnerability report, we are committed to the following:
  • Promptly acknowledge receipt of the report and provide an initial assessment within three business days.
  • Work diligently to validate and reproduce the reported vulnerability.
  • Collaborate with the researcher to address and remediate the vulnerability in a timely manner.
  • Provide appropriate credit and recognition to researchers who adhere to our responsible disclosure guidelines.

6. Exclusions

This policy does not cover:
  • Any vulnerabilities already publicly disclosed.
  • Vulnerabilities in third-party applications or services, even if they interact with our systems.
  • Denial of service (DoS) attacks or brute-force attempts.

7. Legal and ethical considerations

We will not take legal action against researchers who act in good faith and adhere to the guidelines outlined in this policy. However, we expect researchers to comply with all applicable laws and regulations during their testing.

8. Contact Information

For reporting vulnerabilities or inquiries related to this policy, please contact us at: security@greenwheels.com.

9. Policy updates

This Vulnerability Disclosure Policy is subject to periodic updates. We encourage researchers to review this policy regularly before submitting a vulnerability report.
By participating in responsible disclosure, you contribute to a safer digital environment. We sincerely appreciate your collaboration in helping us maintain the security and integrity of our systems.