Hero Background Image

Vulnerability Disclosure Policy

Paperless Parts takes the security of our platform and customer data seriously. If you believe you’ve found a security vulnerability in our systems, we want to hear from you.

How to Report

Email us at [email protected] with a description of the issue, steps to reproduce it, and any supporting evidence (screenshots, request/response logs, etc.).

Please encrypt sensitive details if possible, and avoid including any real customer data in your report.

Scope

This policy applies to security vulnerabilities found in:

  • *.paperlessparts.com and its subdomains
  • Our public-facing web applications and APIs

Out of scope: third-party services we integrate with, social engineering, physical security, and denial-of-service testing.

Our Commitment

  • We’ll acknowledge your report within 7 business days.
  • We’ll investigate and keep you updated on our progress.
  • We’ll let you know once the issue is resolved.

Guidelines for Researchers

  • Give us reasonable time to investigate and fix an issue before disclosing it publicly.
  • Only interact with accounts and data you own or have explicit permission to test.
  • Don’t access, modify, or delete data that isn’t yours.
  • Avoid actions that could degrade service for other users (e.g., spam, DoS).
  • We currently do not offer a paid bug bounty program, but we’re grateful for responsible disclosures.