Security at AutoBuffy

We take security seriously.

AutoBuffy operates an e-commerce platform handling vehicle data, customer orders, and payments. We're committed to protecting our customers and welcoming responsible disclosure from the security research community.

Last updated: May 14, 2026

How to report a security issue

Email [email protected]. This is monitored by AutoBuffy's security team. Please include:

  • A clear description of the vulnerability and its potential impact
  • Steps to reproduce, with example URLs, payloads, or screenshots
  • The affected endpoint, page, or component
  • Your name or handle, if you'd like credit (optional)

We aim to acknowledge reports within 2 business days and provide a substantive update (triage decision, fix timeline, or further questions) within 7 business days.

Safe harbor for good-faith research

We will not pursue legal action against, or notify law enforcement of, security researchers who:

  • Make a good-faith effort to comply with this policy
  • Report findings to [email protected] and give us reasonable time to remediate before disclosing publicly
  • Avoid privacy violations, destruction of data, or service disruption
  • Do not exploit a finding beyond what is necessary to demonstrate it
  • Do not attempt social engineering of AutoBuffy staff or customers

If in doubt, contact us before testing. We'd rather have a conversation than discover testing after the fact.

In scope

The following are considered in scope for security testing:

  • autobuffy.com and all subdomains
  • AutoBuffy public API endpoints
  • AutoBuffy mobile and web checkout flows

Vulnerability classes of particular interest:

  • Authentication / authorization flaws
  • Sensitive data exposure (customer PII, payment data)
  • Injection (SQL, command, XSS) and SSRF
  • Business logic flaws affecting orders or pricing
  • Account takeover paths

Out of scope

Please don't spend time on the following — they're known, accepted, or not actionable:

  • Denial of service attacks (volumetric or application-layer)
  • Brute-force attacks against authentication endpoints
  • Social engineering of staff, vendors, or customers
  • Physical attacks against AutoBuffy facilities or staff
  • Reports from automated scanners without a working proof of concept
  • Missing security headers without a demonstrable, exploitable impact
  • SPF/DKIM/DMARC misconfigurations (we monitor these separately)
  • Vulnerabilities in third-party software that we haven't modified
  • Self-XSS or attacks requiring physical access to the victim's device

Our security commitments

  • Encryption in transit: all traffic to autobuffy.com is served over HTTPS with HSTS.
  • Encryption at rest: customer data is stored on encrypted volumes; payment information is never stored on our servers and is handled exclusively by PCI-DSS Level 1 payment processors (Stripe, PayPal).
  • Access controls: administrative access requires authenticated session tokens; sensitive operations are scoped to named admin users, not domain-wide.
  • Monitoring & response: we operate continuous log monitoring with automated anomaly detection and rapid response to suspicious activity.
  • Patching: dependencies are reviewed and patched on a rolling basis. Security-critical patches are deployed within 24 hours of disclosure when feasible.

Coordinated disclosure timeline

Our default disclosure timeline once a valid vulnerability is reported:

  1. Day 0: we acknowledge receipt of the report
  2. Day 1-7: triage, reproduction, and severity assessment
  3. Day 7-30: remediation and deployment
  4. Day 30+: public disclosure with reporter credit, by mutual agreement

For critical severity issues we may compress this timeline substantially; we'll always communicate with you about timing.

Acknowledgments

We're grateful to the researchers who help keep AutoBuffy secure. As we receive valid reports, we'll recognize researchers here (with permission). Want to be credited? Let us know when you submit your report.

For general questions

This page covers security reports only. For order help, customer support, or general inquiries, please email [email protected] — those reach a different team and will be answered faster.