generated: '2026-09-13' method: searched probe: true source: well-known/cox-automotive-security.txt policy: - https://www.coxautoinc.com/responsible-disclosure contact: - https://www.coxautoinc.com/responsible-disclosure - mailto:securitydisclosure@coxautoinc.com evidence: - source: well-known/cox-automotive-security.txt kind: security.txt url: https://www.coxautoinc.com/.well-known/security.txt status: 200 - source: well-known/cox-automotive-manheim-security.txt kind: security.txt url: https://www.manheim.com/.well-known/security.txt status: 200 - source: https://www.coxautoinc.com/responsible-disclosure kind: disclosure-policy-page status: 200 docs: - https://www.coxautoinc.com/responsible-disclosure bug_bounty: offered: false statement: '"Cox Automotive does not offer a bounty program or provide compensation in exchange for security vulnerability submissions at this time."' platform: null safe_harbor: offered: true detail: Research conducted within the terms of the policy is treated as authorised and in good faith; researchers must still comply with applicable law. scope: Cox Automotive web properties, APIs and applications. Named classes include RCE, SQL injection, XXE, authorization bypass, information disclosure, XSS, CSRF, subdomain takeover, file upload flaws, SSRF and API abuse. response_times: acknowledgement: two business days researcher_follow_up: four weeks before requesting an update encryption_key: https://www.coxautoinc.com/.well-known/publickey.asc security_txt: expires: '2026-12-31T23:59:59Z' hosts: - https://www.coxautoinc.com/.well-known/security.txt - https://www.manheim.com/.well-known/security.txt http_status: 200 probed: '2026-09-13' note: The Manheim copy carries TWO Expires fields (2025-12-31 and 2026-12-31). RFC 9116 allows only one; a strict parser may reject the file or take the earlier, already-expired value.