Security & Vulnerability Disclosure
Last updated: May 6, 2026
We take the security of Dr. Vin seriously. If you believe you've found a security issue, we want to hear from you.
Reporting a vulnerability
Email security@drvin.ai with:
- A description of the issue and its impact
- Steps to reproduce, with the URL or endpoint affected
- Any proof-of-concept code or screenshots
- Your name (if you'd like credit) or "anonymous"
We acknowledge reports within 5 business days and aim to fix high-severity issues within 30 days.
Scope
In scope:
drvin.ai and api.drvin.ai- Authentication and authorization flaws (auth bypass, IDOR, broken access control on share tokens)
- Injection vulnerabilities (XSS, SQLi, RCE, SSRF)
- Sensitive data exposure (leaked VINs, license plate text, payment details)
- CSRF on state-changing endpoints
- Logic flaws in the assessment, checkout, or report flow
- License-plate redaction bypass on shared reports
Out of scope:
- Third-party services we don't operate (Stripe, Cloudflare, R2, Google Gemini, NHTSA, PostHog, GA, Meta)
- Rate limiting on public marketing pages
- Missing security headers without demonstrated impact
- Self-XSS or social engineering of our team or users
- Denial of service or volumetric attacks
- Reports from automated scanners with no demonstrated impact
- Issues only reproducible on outdated browsers
Rules of engagement
- Don't access, modify, or delete data that isn't yours. A proof-of-concept is enough.
- Don't test against other users' share tokens or paid reports.
- Don't perform DoS testing or run automated scanners that generate excessive traffic.
- Don't disclose the issue publicly until we've had a chance to fix it, or 90 days have passed, whichever comes first.
Safe harbor
We won't pursue legal action against researchers who make a good-faith effort to comply with this policy, stop testing once a vulnerability is identified, and report findings through the channel above. We treat compliant research as authorized under the Computer Fraud and Abuse Act and similar laws.
Bounty & credit
We don't currently run a paid bug bounty program. We do credit researchers who report valid issues (with permission) once the fix ships.
Machine-readable
Our security.txt file is at /.well-known/security.txt per RFC 9116.