Security and reporting vulnerabilities
1. Overview
We want CarGo to be safe for the people who trust it with their cameras and their vehicles. If you research the security of our own systems in good faith and tell us what you find, we welcome it. This page explains what you may test, how to report, and what we promise in return.
2. Systems in scope
The CarGo website and its API at cargohold.io and its subdomains, the CarGo web app, and the CarGo Android app.
These are not in scope, and you must not test them: Ring and Amazon services; the companies we use to provide CarGo, including our AI providers (listed on our subprocessors page); the Cloudflare and GitHub platforms themselves; and any website or service that belongs to someone else. If you find a problem in one of them, please report it to that company.
3. What we want to hear about
Examples of what we want to hear about:
- Getting around sign-in or permissions, or acting as another account.
- Reading or changing another customer's alerts, stills, vehicles, settings or reports.
- Cross-site scripting, cross-site request forgery, or injection of any kind. This includes making our support assistant reveal data or take an action it should not.
- Making our servers fetch an address of your choosing (server-side request forgery).
- Keys, tokens or passwords exposed in our code, pages or app.
- Getting around our privacy protections, such as the blurring of faces and license plates, or a camera's privacy zones.
We do not accept reports of:
- social engineering or phishing of our staff or customers, and physical attacks;
- denial of service or load testing, and spam;
- output from an automated scanner with no demonstrated impact;
- missing security headers or best practices with no working exploit;
- self-XSS, and clickjacking on pages with no sensitive action;
- problems in other companies' services (see section 2);
- vulnerabilities disclosed publicly in the last 30 days that we have not yet had time to patch;
- remarks about rate limits that have no security impact.
4. Testing rules
- Use only your own CarGo account. If you need a second account to test access between accounts, email us and we will set up a test account for you.
- Never view, download, change or delete another customer's data or video. If you reach it by accident, stop, do not keep it, and report it to us right away.
- Do not slow down or interrupt the service, and do not run automated high-volume tests against cargohold.io.
- Do not try to take over anyone's Ring account, including your own through CarGo.
5. How to report
Email [email protected] with "Security report" in the subject. Please include:
- the page, feature or API address that is affected;
- the steps to reproduce the problem;
- what an attacker could do with it;
- a proof of concept, if you have one;
- how we can contact you, and the name to credit if you want credit.
Please do not put other people's personal data in your report or your screenshots. We do not offer an encryption key for reports yet. If your report needs one, say so in a first short email and we will arrange it.
6. What we commit to
- We confirm that we received your report within 3 business days.
- We keep you informed while we investigate and fix it, and we tell you when it is fixed.
- We keep your report and your identity confidential unless you agree otherwise.
- We aim to fix a confirmed problem within 7 days if it is critical, 30 days if it is high, and 90 days if it is medium.
- We will not take legal action against research done in good faith under this page (see section 9).
7. How we rate severity
We start from the Common Vulnerability Scoring System (CVSS, version 3.1 or 4.0) and adjust for what matters most to our customers. Anything that exposes a customer's video, stills, location, vehicles or account to someone else ranks highest.
8. Rewards
We do not pay cash rewards at this time. With your permission, we will thank you by name on this page once the problem is fixed.
9. Safe harbor
We consider research to be authorized under our Terms of Service, and we will not pursue legal action, when you:
- followed the rules on this page;
- stopped once you had shown the problem;
- did not keep or share anyone else's data;
- gave us reasonable time to fix the problem before telling anyone else.
We treat such research as authorized for the purposes of anti-hacking laws such as the Computer Fraud and Abuse Act, and of anti-circumvention laws such as the Digital Millennium Copyright Act. If a third party takes action against you for research that followed this page, we will make it known that your work was authorized by us. This cannot authorize testing of anyone else's systems.
10. Coordinated disclosure
Please wait to publish anything about a problem until we have shipped a fix, or until 90 days have passed since your report, whichever comes first. Please share your write-up with us before you publish it. With your permission, we will credit you.
11. Contact
Security reports: [email protected]. Our contact details for researchers are also published at /.well-known/security.txt.