AutoLeadStar · Vulnerability Disclosure
Autoleadstar Vulnerability Disclosure
Vulnerability disclosure
AutoLeadStar runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
CompanyAutomotiveCustomer Data PlatformMarketing AutomationDealershipsAdvertisingArtificial IntelligenceConsent ManagementCRMIsrael
Program: Hackerone
security.txt present
Disclosure Policy
Security Contact
Contact
mailto:security@fullpath.com
Source
Vulnerability Disclosure
generated: '2026-08-06'
method: searched
probe: true
source: https://www.fullpath.com/vulnerability-disclosure-policy
also_from: well-known/autoleadstar-security.txt
summary: >-
Fullpath Ltd. publishes a full, CISA-style coordinated vulnerability disclosure policy —
not just a security.txt contact. It grants safe-harbour authorization, names an explicit
in-scope domain list, enumerates unauthorized test methods and out-of-scope issue classes,
and commits to CISA coordination for cross-vendor findings.
policy:
- https://www.fullpath.com/vulnerability-disclosure-policy
contact:
- mailto:security@fullpath.com
policy_last_updated: '2024-07-30'
safe_harbour:
authorized: true
text: >-
"If you make a good faith effort to comply with this policy during your security research,
we will consider your research to be authorized... FullPath will not recommend or pursue
legal action related to your research. Should legal action be initiated by a third party
against you for activities that were conducted in accordance with this policy, we will
make this authorization known."
scope:
in_scope:
- '*.fullpath.com'
- '*.autoleadstar.com'
- '*.40nuggets.com'
out_of_scope:
- Any service not expressly listed, including connected services.
- Vulnerabilities in vendor systems (report to the vendor).
note: >-
api.fullpath.com and developers.fullpath.com both fall under *.fullpath.com, so the
published API surface is explicitly in scope. Fullpath states it will widen scope over time.
unauthorized_test_methods:
- Network denial of service (DoS/DDoS) or anything impairing access to a system or data.
- Physical testing, social engineering (phishing, vishing), non-technical vulnerability testing.
- Intensive intrusive tests (e.g. SQLi that can spike CPU or crash a database; thousands of
requests to the same API endpoint).
excluded_issue_types:
- Out-of-date software reported without a proof of concept.
- Speculative/theoretical reports.
- Automated-tool output without impact analysis.
- Low-severity findings from tools such as Security Headers.
- CSRF with minimal security implication (e.g. logout CSRF).
- Missing cookie flags.
- UI/UX bugs including spelling mistakes.
- Stack traces disclosing information.
- Open ports without a proof-of-concept.
- Banner grabbing.
- robots.txt disclosure.
- Missing SPF/DKIM/DMARC.
researcher_obligations:
- Report as soon as possible after discovery.
- Avoid privacy violations, UX degradation, disruption of production, destruction or manipulation of data.
- Use exploits only to confirm a vulnerability; no data exfiltration, no persistence, no pivoting.
- Allow reasonable remediation time before public disclosure.
- Stop and notify immediately upon encountering sensitive data.
- No high-volume, low-quality report floods.
coordination:
cisa: true
text: >-
"If your findings include newly discovered vulnerabilities that affect all users of a
product or service and not solely FullPath, we may share your report with the
Cybersecurity and Infrastructure Security Agency, where it will be handled under their
coordinated vulnerability disclosure process."
researcher_identity_protected: true
bug_bounty:
present: false
platform: null
note: No HackerOne, Bugcrowd or Intigriti program found. Disclosure is direct-to-email, unpaid.
gaps:
- No published remediation SLA or acknowledgement time commitment.
- No PGP/encryption key offered for reporting (security.txt has no Encryption field).
- No public hall of fame / Acknowledgments page.
- security.txt omits the RFC 9116 REQUIRED Expires field and is missing from the apex host.
- Policy last updated 2024-07-30 — predates the current developers.fullpath.com API portal.
evidence:
- source: https://www.fullpath.com/.well-known/security.txt
http_status: 200
kind: security.txt
- source: https://www.fullpath.com/vulnerability-disclosure-policy
http_status: 200
kind: coordinated vulnerability disclosure policy
- source: https://www.fullpath.com/legal-and-trust/
http_status: 200
kind: Legal & Trust Center security section
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/autoleadstar-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.