generated: '2026-08-06' method: searched probe: true source: https://www.fullpath.com/vulnerability-disclosure-policy also_from: well-known/autoleadstar-security.txt summary: >- Fullpath Ltd. publishes a full, CISA-style coordinated vulnerability disclosure policy — not just a security.txt contact. It grants safe-harbour authorization, names an explicit in-scope domain list, enumerates unauthorized test methods and out-of-scope issue classes, and commits to CISA coordination for cross-vendor findings. policy: - https://www.fullpath.com/vulnerability-disclosure-policy contact: - mailto:security@fullpath.com policy_last_updated: '2024-07-30' safe_harbour: authorized: true text: >- "If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized... FullPath will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, we will make this authorization known." scope: in_scope: - '*.fullpath.com' - '*.autoleadstar.com' - '*.40nuggets.com' out_of_scope: - Any service not expressly listed, including connected services. - Vulnerabilities in vendor systems (report to the vendor). note: >- api.fullpath.com and developers.fullpath.com both fall under *.fullpath.com, so the published API surface is explicitly in scope. Fullpath states it will widen scope over time. unauthorized_test_methods: - Network denial of service (DoS/DDoS) or anything impairing access to a system or data. - Physical testing, social engineering (phishing, vishing), non-technical vulnerability testing. - Intensive intrusive tests (e.g. SQLi that can spike CPU or crash a database; thousands of requests to the same API endpoint). excluded_issue_types: - Out-of-date software reported without a proof of concept. - Speculative/theoretical reports. - Automated-tool output without impact analysis. - Low-severity findings from tools such as Security Headers. - CSRF with minimal security implication (e.g. logout CSRF). - Missing cookie flags. - UI/UX bugs including spelling mistakes. - Stack traces disclosing information. - Open ports without a proof-of-concept. - Banner grabbing. - robots.txt disclosure. - Missing SPF/DKIM/DMARC. researcher_obligations: - Report as soon as possible after discovery. - Avoid privacy violations, UX degradation, disruption of production, destruction or manipulation of data. - Use exploits only to confirm a vulnerability; no data exfiltration, no persistence, no pivoting. - Allow reasonable remediation time before public disclosure. - Stop and notify immediately upon encountering sensitive data. - No high-volume, low-quality report floods. coordination: cisa: true text: >- "If your findings include newly discovered vulnerabilities that affect all users of a product or service and not solely FullPath, we may share your report with the Cybersecurity and Infrastructure Security Agency, where it will be handled under their coordinated vulnerability disclosure process." researcher_identity_protected: true bug_bounty: present: false platform: null note: No HackerOne, Bugcrowd or Intigriti program found. Disclosure is direct-to-email, unpaid. gaps: - No published remediation SLA or acknowledgement time commitment. - No PGP/encryption key offered for reporting (security.txt has no Encryption field). - No public hall of fame / Acknowledgments page. - security.txt omits the RFC 9116 REQUIRED Expires field and is missing from the apex host. - Policy last updated 2024-07-30 — predates the current developers.fullpath.com API portal. evidence: - source: https://www.fullpath.com/.well-known/security.txt http_status: 200 kind: security.txt - source: https://www.fullpath.com/vulnerability-disclosure-policy http_status: 200 kind: coordinated vulnerability disclosure policy - source: https://www.fullpath.com/legal-and-trust/ http_status: 200 kind: Legal & Trust Center security section