Security and reporting vulnerabilities

Last updated October 7, 2026 · Granite Peak Engineering LLC

1. Overview

We want CarGo to be safe for the people who trust it with their cameras and their vehicles. If you research the security of our own systems in good faith and tell us what you find, we welcome it. This page explains what you may test, how to report, and what we promise in return.

2. Systems in scope

The CarGo website and its API at cargohold.io and its subdomains, the CarGo web app, and the CarGo Android app.

These are not in scope, and you must not test them: Ring and Amazon services; the companies we use to provide CarGo, including our AI providers (listed on our subprocessors page); the Cloudflare and GitHub platforms themselves; and any website or service that belongs to someone else. If you find a problem in one of them, please report it to that company.

3. What we want to hear about

Examples of what we want to hear about:

We do not accept reports of:

4. Testing rules

5. How to report

Email [email protected] with "Security report" in the subject. Please include:

Please do not put other people's personal data in your report or your screenshots. We do not offer an encryption key for reports yet. If your report needs one, say so in a first short email and we will arrange it.

6. What we commit to

7. How we rate severity

We start from the Common Vulnerability Scoring System (CVSS, version 3.1 or 4.0) and adjust for what matters most to our customers. Anything that exposes a customer's video, stills, location, vehicles or account to someone else ranks highest.

8. Rewards

We do not pay cash rewards at this time. With your permission, we will thank you by name on this page once the problem is fixed.

9. Safe harbor

We consider research to be authorized under our Terms of Service, and we will not pursue legal action, when you:

We treat such research as authorized for the purposes of anti-hacking laws such as the Computer Fraud and Abuse Act, and of anti-circumvention laws such as the Digital Millennium Copyright Act. If a third party takes action against you for research that followed this page, we will make it known that your work was authorized by us. This cannot authorize testing of anyone else's systems.

10. Coordinated disclosure

Please wait to publish anything about a problem until we have shipped a fix, or until 90 days have passed since your report, whichever comes first. Please share your write-up with us before you publish it. With your permission, we will credit you.

11. Contact

Security reports: [email protected]. Our contact details for researchers are also published at /.well-known/security.txt.