AutoLeadStar · Vulnerability Disclosure

Autoleadstar Vulnerability Disclosure

Vulnerability disclosure

AutoLeadStar runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyAutomotiveCustomer Data PlatformMarketing AutomationDealershipsAdvertisingArtificial IntelligenceConsent ManagementCRMIsrael
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:security@fullpath.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-06'
method: searched
probe: true
source: https://www.fullpath.com/vulnerability-disclosure-policy
also_from: well-known/autoleadstar-security.txt
summary: >-
  Fullpath Ltd. publishes a full, CISA-style coordinated vulnerability disclosure policy —
  not just a security.txt contact. It grants safe-harbour authorization, names an explicit
  in-scope domain list, enumerates unauthorized test methods and out-of-scope issue classes,
  and commits to CISA coordination for cross-vendor findings.

policy:
- https://www.fullpath.com/vulnerability-disclosure-policy
contact:
- mailto:security@fullpath.com
policy_last_updated: '2024-07-30'

safe_harbour:
  authorized: true
  text: >-
    "If you make a good faith effort to comply with this policy during your security research,
    we will consider your research to be authorized... FullPath will not recommend or pursue
    legal action related to your research. Should legal action be initiated by a third party
    against you for activities that were conducted in accordance with this policy, we will
    make this authorization known."

scope:
  in_scope:
  - '*.fullpath.com'
  - '*.autoleadstar.com'
  - '*.40nuggets.com'
  out_of_scope:
  - Any service not expressly listed, including connected services.
  - Vulnerabilities in vendor systems (report to the vendor).
  note: >-
    api.fullpath.com and developers.fullpath.com both fall under *.fullpath.com, so the
    published API surface is explicitly in scope. Fullpath states it will widen scope over time.

unauthorized_test_methods:
- Network denial of service (DoS/DDoS) or anything impairing access to a system or data.
- Physical testing, social engineering (phishing, vishing), non-technical vulnerability testing.
- Intensive intrusive tests (e.g. SQLi that can spike CPU or crash a database; thousands of
  requests to the same API endpoint).

excluded_issue_types:
- Out-of-date software reported without a proof of concept.
- Speculative/theoretical reports.
- Automated-tool output without impact analysis.
- Low-severity findings from tools such as Security Headers.
- CSRF with minimal security implication (e.g. logout CSRF).
- Missing cookie flags.
- UI/UX bugs including spelling mistakes.
- Stack traces disclosing information.
- Open ports without a proof-of-concept.
- Banner grabbing.
- robots.txt disclosure.
- Missing SPF/DKIM/DMARC.

researcher_obligations:
- Report as soon as possible after discovery.
- Avoid privacy violations, UX degradation, disruption of production, destruction or manipulation of data.
- Use exploits only to confirm a vulnerability; no data exfiltration, no persistence, no pivoting.
- Allow reasonable remediation time before public disclosure.
- Stop and notify immediately upon encountering sensitive data.
- No high-volume, low-quality report floods.

coordination:
  cisa: true
  text: >-
    "If your findings include newly discovered vulnerabilities that affect all users of a
    product or service and not solely FullPath, we may share your report with the
    Cybersecurity and Infrastructure Security Agency, where it will be handled under their
    coordinated vulnerability disclosure process."
  researcher_identity_protected: true

bug_bounty:
  present: false
  platform: null
  note: No HackerOne, Bugcrowd or Intigriti program found. Disclosure is direct-to-email, unpaid.

gaps:
- No published remediation SLA or acknowledgement time commitment.
- No PGP/encryption key offered for reporting (security.txt has no Encryption field).
- No public hall of fame / Acknowledgments page.
- security.txt omits the RFC 9116 REQUIRED Expires field and is missing from the apex host.
- Policy last updated 2024-07-30 — predates the current developers.fullpath.com API portal.

evidence:
- source: https://www.fullpath.com/.well-known/security.txt
  http_status: 200
  kind: security.txt
- source: https://www.fullpath.com/vulnerability-disclosure-policy
  http_status: 200
  kind: coordinated vulnerability disclosure policy
- source: https://www.fullpath.com/legal-and-trust/
  http_status: 200
  kind: Legal & Trust Center security section