AutoBase operates this Vulnerability Disclosure Policy (VDP) to receive reports, verify findings, and take appropriate action. We coordinate remediation and disclosure timing with the reporter when needed. This is a reporting channel; AutoBase does not currently operate a separate bug bounty program.

Scope

  • Products developed or distributed by AutoBase, including AutoBase SCADA/HMI and AutoBase Touch
  • Officially distributed AutoBase modules, including PLC communication drivers
  • Official websites and web services operated by AutoBase
  • Reports affecting supported products and versions receive priority. Remediation options depend on the affected version and will be confirmed after review.
  • Please include the exact product name, version and build, operating system, and affected component.

Permitted Research and Prohibited Activities

  • Non-destructive static or dynamic analysis is permitted on systems you own or are explicitly authorized to test, AutoBase-provided test environments, and officially released product files.
  • Live customer SCADA systems, industrial networks, PLCs, and third-party systems are out of scope. The presence of AutoBase software does not grant permission to test a customer system.
  • AutoBase websites and web services are in scope for reporting. Active scanning or attack testing against production services requires prior written authorization.
  • Unauthorized scanning, fuzzing or intrusion attempts; denial-of-service (DoS/DDoS); account compromise; deleting, altering or exfiltrating data; accessing personal or customer data; phishing, social engineering, and physical intrusion are prohibited.
  • If testing affects a service or exposes real information, stop immediately and notify us at the reporting email address.

How to Report

Reporting email
autobasehelp@gmail.com
Subject
[Security Vulnerability Report] Product - Brief summary
Include
Product, version and build · affected component · vulnerability description and impact · minimal, non-destructive reproduction steps or PoC · reporter contact details (anonymous reports are accepted)

Response Process

  1. Acknowledge receipt
  2. Internal validation
    and analysis
  3. Remediation
    and disclosure coordination
  4. Outcome shared

Reporter Protection and Safe Handling

  • We respect good-faith security research conducted within this policy. This policy does not authorize testing third-party systems, infringing third-party rights, or violating applicable laws.
  • Please coordinate the remediation and timing and content of disclosure with AutoBase. Do not publicly disclose vulnerability details or reproduction materials before remediation is complete.
  • Remove or redact passwords, authentication tokens, personal information, and customer data from PoCs, logs, and screenshots. Send only the minimum information needed for validation.
  • We use reporter personal information only as needed to investigate the report and respond.

Rewards

This channel is for vulnerability reporting, validation, remediation, and coordinated disclosure. AutoBase does not currently offer monetary rewards.