If you have discovered a potential security vulnerability on autoliftsupplies.us, we encourage you to contact our security team immediately. We review all legitimate reports and aim to resolve security issues as quickly as possible. Before submitting a report, please review this Vulnerability Disclosure Policy — including our core principles, bounty program rules, reward guidelines, and reporting scope.
FUNDAMENTALS & SAFE HARBOR
If you adhere to the following principles when reporting a security issue to Auto Lift Supplies LLC, we will not initiate legal action or law enforcement investigations against you regarding your report:
- Give us reasonable time to investigate and fix the vulnerability before disclosing it publicly or sharing details with third parties.
- Do not interact with, modify, or access customer accounts or private data without explicit permission from the account owner.
- Make a good-faith effort to avoid privacy violations, service disruptions, or destruction of website data.
- Do not exploit the vulnerability for any purpose beyond demonstrating the initial security risk.
- Comply with all applicable local, state, and federal laws and regulations.
BOUNTY PROGRAM ELIGIBILITY
We recognize and reward security researchers who help protect our platform and customer data by responsibly reporting vulnerabilities. Bounties are awarded at the sole discretion of Auto Lift Supplies LLC based on impact, severity, and report quality.
To qualify for consideration, you must:
- Strictly follow the Fundamentals listed above.
- Report a valid, original security flaw that poses a demonstrable risk to user privacy or system integrity.
- Submit your disclosure directly via email to our dedicated security contact (do not contact staff directly on social media).
- Disclose any accidental privacy violations or minor disruptions immediately in your initial report.
- Understand that priority is determined by technical risk level and response times may vary.
REWARDS & SEVERITY GUIDELINES
Reward amounts are assessed based on impact and exploitability. Reports must include clear, detailed, and reproducible steps. If an issue cannot be reproduced, it is not eligible for a monetary bounty.
- Only the first verified report of a given vulnerability will be rewarded.
- Multiple issues stemming from a single root cause will be treated as one single report.
Maximum Bounty Amounts by Risk Tier:
Critical Severity – Up to $200
Includes major vulnerabilities such as:
- Remote Code Execution (RCE)
- Remote Shell / Command Execution
- Vertical Authentication Bypass / Administrative Privilege Escalation
- SQL Injection leaking sensitive customer database records
- Full unauthorized account takeover
High Severity – Up to $100
Includes issues such as:
- Lateral authentication bypass / Insecure Direct Object References (IDOR) on critical endpoints
- Disclosure of sensitive customer or financial internal data
- Stored Cross-Site Scripting (XSS) affecting other users
- Local File Inclusion (LFI)
- Insecure handling of authentication session cookies
Medium Severity – Up to $50
Includes issues such as:
- Logic flaws in business process or checkout flows
- CSRF on sensitive account actions
Low Severity – Recognition Only
Includes minor findings such as:
- Open Redirects
- Reflected XSS requiring complex user interaction
- Low-sensitivity technical information leaks
REPORTING & CONTACT INFORMATION
Please send all security reports and vulnerability disclosures directly to our security compliance team: