Vulnerability Disclosure Policy

MechanicX welcomes reports from security researchers and customers. This page is maintained by MechanicX and describes how to report an issue and what to expect. Report to admin@mechanicx.co.uk.

How to report

Email admin@mechanicx.co.uk with the subject line "Security report". Please include:

  • A clear description of the issue and its potential impact.
  • Steps to reproduce, including URLs, requests, or a short proof of concept.
  • The date and time of testing and the account or IP you tested from.
  • How you would like to be credited, if at all.

Machine-readable contact details are published at /.well-known/security.txt.

Our response

  • We acknowledge reports within 3 working days.
  • We give an initial assessment and triage outcome within 10 working days.
  • We aim to remediate critical issues within 14 days, and lower-severity issues within 90 days, keeping you updated as we go.
  • We will tell you when the fix is live and, with your permission, credit you publicly.

Scope

In scope:

  • mechanicx.co.uk and www.mechanicx.co.uk
  • The MechanicX web application and its API endpoints

Out of scope:

  • Third-party services we rely on — report those to the provider directly.
  • Findings from automated scanners without a demonstrated, exploitable impact.
  • Missing best-practice headers, cookie flags on non-sensitive values, or version disclosure with no proven exploit path.
  • Social engineering, phishing, or physical attacks against our staff or customers.
  • Denial of service, volumetric testing, or spam of any kind.
  • Self-XSS and issues requiring an already-compromised device or browser.

Testing rules and safe harbour

If you follow this policy in good faith, we will not pursue legal action against you and will treat your work as authorised research. In return, please:

  • Only test against accounts and data you own or have permission to use.
  • Never access, modify, delete, or exfiltrate another garage's data. If you encounter personal data, stop and tell us immediately.
  • Avoid degrading service availability for other users.
  • Give us reasonable time to fix an issue before publishing any details, and coordinate disclosure with us.

We do not currently operate a paid bug bounty. We are happy to provide public credit and a written acknowledgement.

If you are a customer

If you believe your workspace has been accessed without authorisation, email us immediately and change affected passwords. Our security posture is described on the Trust & Security page and data handling on the Privacy Policy.

Last updated 5 August 2026.

v2026.08.05.1008