Stationwise welcomes reports of suspected security vulnerabilities in our platform from the security research community.
Email security@stationwise.com with a description of the issue, the affected component or URL, and steps to reproduce.
We acknowledge reports within 3 business days, provide an assessment and expected remediation timeline within 10 business days, and notify you when the issue is resolved.
The Stationwise web application and public APIs. Out of scope: denial-of-service testing, social engineering, physical attacks, and findings that require access to a compromised account or device.
We will not pursue legal action against researchers who report vulnerabilities in good faith, act within this policy’s scope, avoid privacy violations and service degradation, and give us reasonable time to remediate before public disclosure.