generated: '2026-08-26' method: searched source: https://www.paperlessparts.com/vulnerability-disclosure-policy/ program: published: true type: vulnerability-disclosure-policy url: https://www.paperlessparts.com/vulnerability-disclosure-policy/ linked_from: https://www.paperlessparts.com/security/ http_status: 200 bug_bounty: false bounty_note: >- "We currently do not offer a paid bug bounty program, but we're grateful for responsible disclosures." (verbatim from the policy page) platform: none — reported directly by email, not via HackerOne / Bugcrowd / Intigriti contact: method: email address: obfuscated on the page by a Cloudflare email-protection script; the human-readable address is not exposed to an unauthenticated crawler note: >- The policy says "Email us at [protected address] with a description of the issue, steps to reproduce it, and any supporting evidence". The address itself is behind Cloudflare email-obfuscation, so it is deliberately not transcribed here. pgp: not published encryption_request: "Please encrypt sensitive details if possible" scope: in_scope: - '*.paperlessparts.com and its subdomains' - Paperless Parts public-facing web applications and APIs out_of_scope: - third-party services Paperless Parts integrates with - social engineering - physical security - denial-of-service testing commitments: acknowledgement: within 7 business days updates: "We'll investigate and keep you updated on our progress" resolution_notice: "We'll let you know once the issue is resolved" researcher_guidelines: - give Paperless Parts reasonable time to investigate and fix before public disclosure - only interact with accounts and data you own or have explicit permission to test - do not access, modify or delete data that is not yours - avoid actions that could degrade service for other users security_txt: published: false probed: - url: https://www.paperlessparts.com/.well-known/security.txt status: 404 - url: https://api.paperlessparts.com/.well-known/security.txt status: 404 note: >- A real disclosure policy exists but it is not machine-discoverable — publishing an RFC 9116 security.txt pointing at this page would be a one-line fix.