May Mobility · Vulnerability Disclosure

May Mobility Vulnerability Disclosure

Vulnerability disclosure

May Mobility runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyAutonomous VehiclesTransportationMobilityRobotaxiFleet ManagementTelemetryPublic TransitAutomotiveStreaming
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:security@maymobility.com

Source

Vulnerability Disclosure

may-mobility-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-01'
method: searched
probe: true
source: https://net.maymobility.com/docs/policies/security
policy:
- https://net.maymobility.com/docs/policies/security
contact:
- mailto:security@maymobility.com
encryption:
- https://net.maymobility.com/NOC_0x71B84C17_public.txt
preferred_languages:
- en
program:
  name: Responsible Disclosure at May
  type: responsible-disclosure
  bug_bounty: false
  bounty_platform: null
  rewards: discretionary
  rewards_note: 'Policy states "May Mobility will provide compensation for disclosed
    vulnerabilites as we deem fit." No fixed bounty table is published and no
    HackerOne / Bugcrowd / Intigriti program was found.'
  safe_harbor: true
  safe_harbor_note: 'May Mobility agrees not to pursue civil action against
    researchers acting in good faith under the published Terms; good-faith research
    consistent with the Terms is treated as "authorized" conduct under the Computer
    Fraud and Abuse Act, no DMCA claim will be brought for circumventing protective
    technical measures, and May Mobility will attest to a third party that the
    research complied with the Terms if asked.'
  coordinated_disclosure: true
  coordinated_disclosure_note: Public disclosure requires prior consent from May
    Mobility.
out_of_scope:
- item: May Mobility shuttles / vehicles
  reason: 'Explicitly excluded. "May Mobility shuttles are not in scope for
    vulnerability disclosure, and should never be the subject of external security
    research. This policy is to ensure the continued safety of the public and May
    employees."'
  note: A safety-critical carve-out that is unusual outside physical-world
    operators, and is the defining feature of this provider's disclosure posture.
researcher_obligations:
- Do not put the safety of riders, customers or employees, or the integrity of the
  fleet, in jeopardy.
- Do not use identified vulnerabilities for further information gathering or
  exploitation.
- Do not access other users' data beyond your own accounts or accounts you have
  explicit permission to access.
- On incidental exposure of data you may not access, do not save, store, copy or
  transfer it; report immediately for safe-harbor coverage.
- Do not publicly disclose without prior consent.
- Do not extort or make ransom / compensation demands.
- Follow all applicable laws including export control, sanctions and embargo
  regulations.
evidence:
- source: well-known/may-mobility-security.txt
  kind: security.txt
  note: RFC 9116, PGP-signed. Carries Contact, Encryption, Policy and two Canonical
    entries.
- source: https://net.maymobility.com/docs/policies/security
  kind: disclosure-policy-page
  http_status: 200
x-findings:
- id: security-txt-expired
  severity: low
  detail: 'The published security.txt declares Expires: 2025-05-25T16:00:00.000Z.
    As observed on 2026-08-01 the document is past its own stated expiry, which
    RFC 9116 section 2.5.5 says means it should no longer be relied upon. The
    contact and policy targets both still resolve.'
- id: canonical-path-mismatch
  severity: informational
  detail: The document lists https://net.maymobility.com/security.txt as a Canonical
    location, but that host serves the file at the bare /security.txt root rather
    than the RFC 9116 /.well-known/security.txt path (404 there).