generated: '2026-07-18' method: searched probe: true source: https://www.cars24.com/security/ policy: - https://www.cars24.com/security/ contact: - cyber-security@cars24.com program: type: vulnerability-disclosure-and-bug-bounty in_scope: - "*.cars24.com web applications" - iOS and Android mobile apps - backend services and APIs rewards: >- Hall of Fame recognition and acknowledgement, tiered by severity (P1-P4); higher-severity findings are eligible for bounties. sla: first_response: 7 business days closure_target: 10-15 business days safe_harbor: >- Cars24 supports ethical research and will not take legal action against researchers who comply with the program's rules. Researchers agree to an NDA and must not disclose details to third parties without written consent. evidence: - source: https://www.cars24.com/security/ kind: disclosure page keywords: - vulnerability - bug bounty - responsible disclosure - safe harbor - security contact notes: >- /.well-known/security.txt returns HTTP 410 (not published); the disclosure program lives on the human-readable /security/ page.