Skip to main content

Vulnerability Disclosure Policy

Found a security issue? We want to hear about it — and we will work with you in good faith to get it fixed.

How to report

  1. 1Email security@platemastr.app with a clear description of the issue.
  2. 2Include the steps to reproduce, the affected URL or endpoint, and the impact you observed.
  3. 3If you can, attach a proof-of-concept (screenshots, a request/response, or a short script).
  4. 4Give us reasonable time to investigate and fix before any public disclosure.
security@platemastr.app

What to expect from us

  • We acknowledge every good-faith report and will confirm receipt.
  • We investigate promptly and keep you updated on our progress.
  • We remediate confirmed critical issues within 7 days (our internal target is immediate).
  • We credit reporters who wish to be acknowledged, once a fix has shipped.

Safe harbor

If you make a good-faith effort to follow this policy during your research, we will consider your testing authorized, we will not pursue or support legal action against you, and we will work with you to understand and resolve the issue quickly. Good faith means: you stay within the scope below, you do not access or modify other customers’ data beyond the minimum needed to demonstrate the issue, and you give us a reasonable window to remediate before any public disclosure.

In scope

  • The PlateMastr web application at platemastr.app and its API.
  • Authentication, authorization, and tenant-isolation flaws.
  • Injection, data-exposure, and access-control issues.

Out of scope

  • Denial-of-service (DoS/DDoS) or volumetric load testing.
  • Social engineering, phishing, or physical attacks against staff.
  • Findings that require a compromised device, rooted phone, or stolen credentials.
  • Reports from automated scanners with no demonstrated, reproducible impact.
  • Issues in third-party services we use (report those to the vendor directly).

The machine-readable version of this contact lives at /.well-known/security.txt. PlateMastr LLC — Last updated June 2026.