generated: '2026-08-01' method: searched probe: true source: https://net.maymobility.com/docs/policies/security policy: - https://net.maymobility.com/docs/policies/security contact: - mailto:security@maymobility.com encryption: - https://net.maymobility.com/NOC_0x71B84C17_public.txt preferred_languages: - en program: name: Responsible Disclosure at May type: responsible-disclosure bug_bounty: false bounty_platform: null rewards: discretionary rewards_note: 'Policy states "May Mobility will provide compensation for disclosed vulnerabilites as we deem fit." No fixed bounty table is published and no HackerOne / Bugcrowd / Intigriti program was found.' safe_harbor: true safe_harbor_note: 'May Mobility agrees not to pursue civil action against researchers acting in good faith under the published Terms; good-faith research consistent with the Terms is treated as "authorized" conduct under the Computer Fraud and Abuse Act, no DMCA claim will be brought for circumventing protective technical measures, and May Mobility will attest to a third party that the research complied with the Terms if asked.' coordinated_disclosure: true coordinated_disclosure_note: Public disclosure requires prior consent from May Mobility. out_of_scope: - item: May Mobility shuttles / vehicles reason: 'Explicitly excluded. "May Mobility shuttles are not in scope for vulnerability disclosure, and should never be the subject of external security research. This policy is to ensure the continued safety of the public and May employees."' note: A safety-critical carve-out that is unusual outside physical-world operators, and is the defining feature of this provider's disclosure posture. researcher_obligations: - Do not put the safety of riders, customers or employees, or the integrity of the fleet, in jeopardy. - Do not use identified vulnerabilities for further information gathering or exploitation. - Do not access other users' data beyond your own accounts or accounts you have explicit permission to access. - On incidental exposure of data you may not access, do not save, store, copy or transfer it; report immediately for safe-harbor coverage. - Do not publicly disclose without prior consent. - Do not extort or make ransom / compensation demands. - Follow all applicable laws including export control, sanctions and embargo regulations. evidence: - source: well-known/may-mobility-security.txt kind: security.txt note: RFC 9116, PGP-signed. Carries Contact, Encryption, Policy and two Canonical entries. - source: https://net.maymobility.com/docs/policies/security kind: disclosure-policy-page http_status: 200 x-findings: - id: security-txt-expired severity: low detail: 'The published security.txt declares Expires: 2025-05-25T16:00:00.000Z. As observed on 2026-08-01 the document is past its own stated expiry, which RFC 9116 section 2.5.5 says means it should no longer be relied upon. The contact and policy targets both still resolve.' - id: canonical-path-mismatch severity: informational detail: The document lists https://net.maymobility.com/security.txt as a Canonical location, but that host serves the file at the bare /security.txt root rather than the RFC 9116 /.well-known/security.txt path (404 there).