AutoFi · Vulnerability Disclosure

Autofi Vulnerability Disclosure

Vulnerability disclosure

AutoFi runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyAutomotiveFintechDigital RetailAuto FinanceDealershipsSales EnablementSaaSLendingLoan OriginationCredit DecisioningPayment CalculationPrequalification
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
security@autofi.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-14'
method: searched
probe: true
policy:
- https://trust.autofi.com/
contact:
- security@autofi.com
bug_bounty:
  program: null
  platform: null
  note: No HackerOne, Bugcrowd or Intigriti program was found for AutoFi.
security_txt:
  served: false
  note: >-
    /.well-known/security.txt returns 404 on every AutoFi host probed
    (autofi.com, www, api, api-uat, auth, lender, portal) on 2026-08-14. See
    well-known/autofi-well-known.yml.
disclosure_statement: >-
  AutoFi's trust portal invites vulnerability reports directly: "If you think you
  may have discovered a vulnerability, please send us a note" — linking to
  security@autofi.com with a "Responsible Disclosure Report for AutoFi" subject.
evidence:
- source: https://trust.autofi.com/
  kind: trust-portal-disclosure-invitation
  http_status: 200
  fetched: '2026-08-14'
- source: https://autofi.com/.well-known/security.txt
  kind: security.txt
  http_status: 404
  fetched: '2026-08-14'
notes:
- >-
  The automated probe (0-working/probe-security-programs.py) records vdp=none
  because the SafeBase trust portal renders client-side and returns no
  disclosure keywords to a plain fetch. This file is method:searched from the
  rendered page and must not be overwritten by the probe.
- >-
  Publishing an RFC 9116 /.well-known/security.txt pointing at
  security@autofi.com and https://trust.autofi.com/ would make this program
  machine-discoverable; today it is only reachable by a human reading the portal.