Security policy
We take security reports seriously. If you've found a vulnerability in Haulwright, please tell us before disclosing publicly. We'll respond within 48 hours and credit you in the hall of fame below if your report leads to a fix.
Reporting a vulnerability
Email security@fidalgosystems.com with a clear description of the issue, steps to reproduce, and the impact. PGP-encrypted reports welcome but not required.
Scope
In scope:
- The Haulwright web application (this site and its API)
- The driver mobile app
- Public APIs documented at /api
Out of scope:
- Social engineering, phishing, physical security, or denial-of- service attacks against our infrastructure.
- Issues in third-party services we use (Vercel, Postgres providers, Auth.js, etc.) — please report those upstream first.
- Theoretical issues without a concrete impact (e.g. "this could be exploited if X were also true and Y also happened").
What we ask of researchers
- Don't access, modify, or destroy customer data.
- Don't run automated scanners against production at high rates — please test on a sandbox account if you need to throw load.
- Give us 90 days from your initial report before public disclosure.
What you get from us
- Acknowledgment within 48 hours.
- A status update at least weekly while we triage and fix.
- A public credit (with your preferred handle) once the fix ships.
- No legal action against good-faith researchers operating within scope.
Hall of fame
No reports yet. If you find something, you'll be the first name on this list.