If you discover a potential security vulnerability affecting Greens Car Spares, we encourage you to report it to us as soon as possible.
We review legitimate vulnerability reports and will make reasonable efforts to investigate and resolve confirmed security issues promptly.
Before submitting a report, please review this policy carefully, including our responsible disclosure principles, bounty programme requirements, reward guidelines, and examples of issues that may qualify.
1. RESPONSIBLE DISCLOSURE PRINCIPLES
If you follow the principles below while researching and reporting a potential security issue affecting Greens Car Spares, we will not initiate legal action or an enforcement investigation against you solely as a result of your good-faith security research.
We ask that you:
- Give us reasonable time to investigate and resolve any vulnerability you report before publicly disclosing the issue or sharing details with third parties.
- Do not access, modify, or interact with another person's private account or data unless the account owner has explicitly authorised you to do so.
- Make a good-faith effort to avoid privacy violations, data loss, service disruption, or harm to other users.
- Do not exploit any security vulnerability beyond what is reasonably necessary to demonstrate that the vulnerability exists.
- Do not attempt to access sensitive company information, compromise additional systems, or search for unrelated vulnerabilities once the reported issue has been demonstrated.
- Do not violate any applicable laws, regulations, or third-party rights while conducting security research.
2. BOUNTY PROGRAMME
Greens Car Spares appreciates the efforts of security researchers who help us identify vulnerabilities and improve the security of our services.
Any monetary bounty is awarded entirely at the discretion of Greens Car Spares and may depend on factors including severity, impact, exploitability, report quality, and whether the vulnerability has already been reported.
To potentially qualify for a bounty, you must:
- Follow the Responsible Disclosure Principles described above.
- Report a genuine security vulnerability affecting our website, services, systems, or infrastructure that creates a meaningful security or privacy risk.
- Submit your security report directly to Greens Car Spares using our official contact details.
- Avoid contacting individual employees directly regarding security vulnerabilities.
- Clearly disclose in your report if you accidentally accessed private information, account data, system configurations, credentials, or other confidential information while investigating the issue.
- Provide sufficient information for us to investigate and reproduce the vulnerability.
We aim to investigate valid reports as promptly as reasonably possible. Response times may vary depending on the severity of the reported issue, the complexity of the investigation, and the number of reports received.
Greens Car Spares reserves the right to disclose or publish information about reported vulnerabilities after they have been appropriately addressed.
3. REWARD GUIDELINES
Rewards are generally determined according to the potential impact and severity of a confirmed vulnerability.
Our bounty programme and reward amounts may be updated from time to time.
To be considered for a reward:
- Reports should contain clear and detailed reproduction steps.
- Reports that do not contain sufficient information to reproduce or verify the vulnerability may not qualify for a bounty.
- If multiple researchers report the same vulnerability, the reward will generally be awarded to the first report that allows us to fully reproduce and confirm the issue.
- Multiple vulnerabilities resulting from the same underlying security flaw may be treated as a single vulnerability for reward purposes.
Reward amounts are determined at the discretion of Greens Car Spares based on factors including:
- Potential impact;
- Severity;
- Ease of exploitation;
- Number of affected users or systems;
- Quality of the report; and
- Complexity of remediation.
The amounts below represent the maximum potential bounty for each severity level.
Critical Severity Vulnerabilities — Up to £200
Critical vulnerabilities are security issues that may allow significant unauthorised access, complete system compromise, remote code execution, serious financial loss, or administrative privilege escalation.
Examples may include:
- Remote Code Execution;
- Remote shell or command execution;
- Vertical authentication or authorisation bypass;
- SQL injection exposing sensitive or targeted information;
- Complete unauthorised access to customer or administrative accounts;
- Privilege escalation from an ordinary user to an administrator.
High Severity Vulnerabilities — Up to £100
High-severity vulnerabilities are issues that may significantly affect the security of our systems, customers, accounts, or business operations.
Examples may include:
- Horizontal or lateral authentication bypass;
- Exposure of significant confidential or internal information;
- Stored Cross-Site Scripting (XSS) affecting other users;
- Local File Inclusion;
- Insecure handling of authentication cookies or session information;
- Serious access-control vulnerabilities.
Medium Severity Vulnerabilities — Up to £50
Medium-severity vulnerabilities are issues that may affect multiple users or systems and require little or limited user interaction to exploit.
Examples may include:
- Business logic vulnerabilities;
- Significant process or workflow security flaws;
- Insecure Direct Object References (IDOR);
- Improper access controls affecting user information or functionality.
Low Severity Vulnerabilities
Low-severity vulnerabilities generally affect individual users, have limited impact, or require significant user interaction or specific prerequisites to exploit.
Examples may include:
- Open redirects;
- Reflected Cross-Site Scripting (XSS);
- Low-sensitivity information disclosure;
- Issues requiring a Man-in-the-Middle (MITM) position or other significant prerequisites.
Low-severity issues may not qualify for a monetary reward.
4. ISSUES THAT MAY NOT QUALIFY
Reports may be considered ineligible for a bounty where they:
- Do not demonstrate a meaningful security impact;
- Depend entirely on outdated or unsupported software outside our control;
- Require physical access to a user's device;
- Are purely theoretical and cannot be reasonably demonstrated;
- Are duplicates of previously reported vulnerabilities;
- Relate only to minor configuration or informational issues without meaningful security consequences;
- Depend on social engineering, phishing, or fraudulent activity;
- Require denial-of-service or disruptive testing;
- Involve automated scanning that causes excessive traffic or service disruption;
- Result from activities that breach this policy or applicable law.
Greens Car Spares retains final discretion regarding whether a vulnerability qualifies for the programme and whether any reward will be issued.
5. REPORTING A SECURITY VULNERABILITY
Please provide as much detail as possible when submitting a vulnerability report, including:
- A clear description of the vulnerability;
- The affected page, system, feature, or service;
- Steps required to reproduce the issue;
- Relevant screenshots or technical details where appropriate;
- Potential security impact;
- Any actions you took while investigating the vulnerability; and
- Your preferred contact information.
Please do not include unnecessary personal information, customer information, passwords, payment details, or other sensitive data in your report.
CONTACT US
To report a security vulnerability or ask a question about this policy, please contact:
Greens Car Spares
Address: 31 Main St, Swallownest, Sheffield S26 4TZ, UK
Telephone: +44 114 287 2757
Email: info@greenscarspares.co.uk