✓ Report to security@mydiygarage.com
✓ Machine-readable pointer: /.well-known/security.txt
✓ Critical & High issues patched within 72 hours of confirmation
✓ Good-faith research covered by our safe-harbor terms below
How to report
Send a report to security@mydiygarage.com. For sensitive reports, you may instead open a GitHub private security advisory — this gives us an encrypted, tracked channel without needing our PGP key.
Please include:
- A clear description of the issue and its impact.
- Steps to reproduce, or a proof-of-concept — the more concrete, the faster we can triage.
- The affected URL(s) and, if known, the affected component (auth, vehicle, diagnostics, maintenance, analytics, notifications, marketing site, or PWA).
- Your preferred name / handle for credit in the release note, if you'd like credit — otherwise we treat the report as anonymous.
We reply from security@mydiygarage.com. If you don't hear back within the acknowledgement window below, please resend from a different address or open a private advisory — it may have been caught in filtering.
What we commit to
Business day = US/Central, Monday–Friday, excluding US federal holidays. The clock starts when your report arrives.
| Severity | Acknowledge | Triage complete | Patch in production |
|---|---|---|---|
| Critical | ≤ 1 business day | ≤ 2 business days | ≤ 72 hours from confirmation |
| High | ≤ 2 business days | ≤ 3 business days | ≤ 72 hours from confirmation |
| Medium | ≤ 3 business days | ≤ 5 business days | ≤ 30 days from confirmation |
| Low | ≤ 5 business days | ≤ 10 business days | Next reasonable release |
"Confirmation" means we've reproduced the issue (or accepted a compelling proof-of-concept) and assigned a severity. If a fix requires coordinating with a third party or a data migration and 72 hours isn't feasible, we'll tell you why and give you a realistic target.
In scope
app.mydiygarage.com— the SaaS application (PWA and its backing microservices).api.mydiygarage.com— the public API surface.mydiygarage.comandwww.mydiygarage.com— the marketing site.- The official MyDIYGarage mobile apps on the App Store and Google Play.
- Any subdomain of
mydiygarage.comthat we operate directly.
Out of scope
The following are outside this policy and will be closed at triage with a pointer here — please don't spend your time on them:
- Denial-of-service, volumetric attacks, brute-forcing, or anything that would degrade service for other users.
- Social engineering (phishing, vishing, pretexting) targeting our staff, our vendors, or our customers.
- Physical intrusion or attacks against staff.
- Automated scanner output without a demonstrated exploit chain (e.g. "missing header" reports on public marketing pages, TLS-config nits already flagged by SSL Labs).
- Reports about email-header configuration (SPF, DKIM, DMARC) unless you can show real exploit impact.
- Issues in third-party services we integrate with (Stripe, AWS, Cognito, etc.) — please report those to the vendor. We're happy to help you coordinate if the impact touches our users.
- Vulnerabilities that require a rooted or jailbroken device, or a browser more than two major versions out of date.
- Any activity that accesses, modifies, exfiltrates, or destroys data belonging to another user or the business.
Safe harbor
If you make a good-faith effort to comply with this policy, we will:
- Consider your research authorized under our Terms of Service and the U.S. Computer Fraud and Abuse Act (CFAA), and we will not pursue civil action or refer the matter for prosecution.
- Waive claims under the Digital Millennium Copyright Act (DMCA) for the research activity described in this policy.
- Work with you to understand and resolve the issue quickly, and — if you'd like credit — publicly acknowledge your contribution when we disclose.
Good-faith research means: you tested only against your own account (or a synthetic one you created), you did not access, modify, or destroy anyone else's data, you did not disrupt service, and you gave us a reasonable window to fix the issue before publishing.
Coordinated disclosure
Our default disclosure window is 90 days from confirmation. We may agree with you to publish sooner (e.g., a fix ships fast) or later (e.g., a third-party vendor needs more time). If we observe active in-the-wild exploitation, we'll publish mitigations first and detailed disclosure after the fix is deployed.
Public disclosure typically appears in a note on our What's New page and, when appropriate, a GitHub Security Advisory that credits you (with your consent) and links to the assigned CVE.
Rewards
We do not currently run a paid bug-bounty program. We do offer credit in the release note and the security advisory when you'd like it, and — for exceptional finds — we're happy to send a thank-you.
Questions
For anything not covered here, write to security@mydiygarage.com. For general contact, see hello@mydiygarage.com. Privacy questions go to privacy@mydiygarage.com and legal to legal@mydiygarage.com.
Nielsen Digital, LLC
c/o Northwest Registered Agent, LLC
5900 Balcones Drive, Suite 100
Austin, TX 78731
United States