Responsible Disclosure
Last updated July 8, 2026 · v1.0
Fuel Relay handles fueling records that companies bill against, so we take security reports seriously. If you find a vulnerability, we want to hear about it, and we will not punish good-faith research.
1. Scope
In scope:
- The production website and admin dashboard (this site).
- The production APIs behind the app and dashboard.
- The released Fuel Relay mobile app binaries.
Out of scope:
- Test and staging environments.
- Third-party services we use (Stripe, Supabase, Vercel, and the rest of our sub-processor list). Report issues in those directly to the vendor.
- Social engineering, phishing, and physical attacks.
- Denial-of-service testing of any kind.
Only test against accounts and organizations you own. Never access, modify, or delete another customer's data.
2. Safe harbor
We will not pursue legal action against you for security research conducted in good faith that follows this policy. Good faith means: you avoid privacy violations and service degradation, you do not destroy or exfiltrate data beyond the minimum needed to demonstrate the issue, you report promptly, and you give us a reasonable window to fix the issue before any public disclosure. If you are unsure whether something is covered, ask first at security@fuelrelay.net.
3. Out-of-scope vulnerabilities
These are known and accepted; reports about them will not qualify:
- Missing security headers on public marketing pages.
- Self-XSS, or issues that require the victim to attack themselves.
- Theoretical CSRF on non-mutating (read-only) endpoints.
- Clickjacking on pages with no sensitive actions.
- Software version disclosure without a working exploit.
- Automated scanner output without a demonstrated impact.
- Email SPF, DKIM, or DMARC configuration opinions without a working spoof.
- Rate-limit observations without demonstrated security impact.
4. Reporting
Email security@fuelrelay.net with steps to reproduce, the impact you believe the issue has, and any proof-of-concept material. Machine-readable details live at /.well-known/security.txt.
- We acknowledge reports within 3 business days.
- We keep you informed while we investigate and fix.
- Please keep the issue confidential until we have shipped a fix and agreed on disclosure timing.
5. What we offer
We offer recognition first: with your permission, valid reports are credited in the acknowledgments below. We plan to add a paid bug bounty after the service has been in production for 90 days; until then, rewards are at our discretion.
Acknowledgments
No public reports yet. Researchers who make a valid report are listed here with their permission.