We take reports seriously and we would rather hear from you than not. If you believe you have found a vulnerability in machineaction.com, write to security@machineaction.com with enough detail to reproduce it.
Our commitment#
- We acknowledge reports within three business days.
- We will keep you updated while we investigate and tell you when it is resolved.
- We will not pursue legal action against researchers who act in good faith and follow the rules below.
In scope#
- machineaction.com and its subdomains.
- The preorder signup, garage, referral and invitation flows.
Out of scope#
- Denial-of-service, volumetric or automated stress testing.
- Social engineering of our team, customers or vendors.
- Reports generated solely by scanners with no demonstrated impact.
- Issues in third-party services we do not control.
Ground rules#
Please use your own account and test data, do not access or modify other people’s information, do not degrade the service for others, and give us reasonable time to fix an issue before disclosing it publicly.
Protections in place#
At a high level: traffic is served over HTTPS with strict transport security, the signup flow is protected by an invisible bot challenge and rate limiting, email addresses are verified before a referral is credited, database access is governed by row-level policies, and administrative surfaces are separately gated.
Contact#
Machine Action Inc., One Embarcadero Center, Suite 1200, San Francisco, CA 94111, United States
Questions about this document: security@machineaction.com