Vulnerability Disclosure Policy
Paperless Parts takes the security of our platform and customer data seriously. If you believe you’ve found a security vulnerability in our systems, we want to hear from you.
How to Report
Email us at [email protected] with a description of the issue, steps to reproduce it, and any supporting evidence (screenshots, request/response logs, etc.).
Please encrypt sensitive details if possible, and avoid including any real customer data in your report.
Scope
This policy applies to security vulnerabilities found in:
- *.paperlessparts.com and its subdomains
- Our public-facing web applications and APIs
Out of scope: third-party services we integrate with, social engineering, physical security, and denial-of-service testing.
Our Commitment
- We’ll acknowledge your report within 7 business days.
- We’ll investigate and keep you updated on our progress.
- We’ll let you know once the issue is resolved.
Guidelines for Researchers
- Give us reasonable time to investigate and fix an issue before disclosing it publicly.
- Only interact with accounts and data you own or have explicit permission to test.
- Don’t access, modify, or delete data that isn’t yours.
- Avoid actions that could degrade service for other users (e.g., spam, DoS).
- We currently do not offer a paid bug bounty program, but we’re grateful for responsible disclosures.