Reporting a security flaw.
This standard describes credit applications, consent records and customer data. A flaw in how it specifies those is a flaw worth fixing in public. Here is how to tell us about one.
council@automotivemcp.ai with SECURITY: at the start of the subject line.
Machine-readable at /.well-known/security.txt.
What is in scope
- The specification. A requirement that, if implemented exactly as written, would expose customer data, weaken authentication, or let one dealership read another’s records. The Auth & Security Profile is the most important section to attack.
- The schemas. A field carrying personal or financial data that is not marked
x-pii, or an example instance containing something that looks like real customer data. - This site. Anything exploitable on automotivemcp.ai, including the schema endpoints under
/schemas/.
What is not
Vulnerabilities in a vendor’s own implementation belong with that vendor, not with us, because the council does not operate any dealership system. Report those to the vendor directly. If a vendor flaw is caused by following this specification, that is in scope and we want to hear it.
What we commit to
- Acknowledgement within 5 business days that a human has read your report.
- An assessment within 30 days: whether we agree it is a flaw, and what we intend to do.
- A public fix. Specification and schema flaws are corrected in the open, noted on the Updates page, and credited to you by name unless you ask otherwise.
We ask for 90 days before public disclosure, and we will say so plainly if we need longer. There is no bug bounty; this is a draft standard run by a small group, and we would rather be honest about that than advertise a program we cannot staff.
Safe harbour
Research conducted in good faith under this policy (against this site and the published artifacts, without accessing anyone else’s data, degrading service, or acting beyond what is needed to demonstrate the flaw) will not be pursued by us. Do not test against a live dealership system. Those are other people’s customers.