Purpose Statement At Turo, we are committed to protecting the trust and security of our community. The purpose of our Vulnerability Disclosure Program (VDP) is to foster a collaborative relationship with security researchers, developers, and the broader security community. This program provides a structured and transparent channel for identifying and responsibly reporting security vulnerabilities within Turo's platform, mobile apps, and infrastructure. Through this initiative, we aim to enhance the safety of our platform by addressing potential vulnerabilities proactively, reducing risks, and maintaining the privacy and integrity of our users’ data. We encourage responsible disclosure practices and appreciate the contributions of ethical hackers and researchers. Together, we can ensure that Turo remains a safe and reliable platform for connecting people who need vehicles with the hosts. How to Engage in Private Bug Bounty Program In order for us to invite you to our private HackerOne Bug Bounty Program email us at mailto:security-compliance@turo.com using the following format: ===================================================================== Subject: Turo Bug Bounty Program - Vulnerability Disclosure Request. Body: Your HackerOne username Email associated with your HackerOne account Reputation on HackerOne (optional) ===================================================================== Note: If you do not have an account on HackerOne please create one! Scope At Turo, we value the security community and welcome security researchers to help us identify vulnerabilities to protect our users, partners, and platform. Below is a detailed outline of what assets and vulnerability types fall within the scope of our Vulnerability Disclosure Program (VDP). In-Scope Assets and Properties The following Turo assets and products are considered within scope for vulnerability testing: Web Applications *.turo.com [Maximum Severity : Critical] *.turo.xyz [Maximum Severity : High] *.relayrides.com [Maximum Severity : Medium] Following Third-party services, vendors, and integrations not operated or controlled by Turo. Turo BBP SLAs will not be applicable for reports pertaining to these assets as these are not owned by Turo. explore.turo.com [Maximum Severity : Low] blog.turo.com [Maximum Severity : Low] shop.turo.com [Maximum Severity : Low] openroad.turo.com [Maximum Severity : Low] Mobile Applications - Turo iOS App : App Store 555063314 (Please sign up for your Turo Account to test and report vulnerabilities.) - Turo Android App : Play Store com.relayrides.android.relayrides (Please create your own Turo Account to test and report any issues.) Infrastructure - Turo-owned cloud-based infrastructure that supports web and mobile services. - API endpoints used for communication between Turo’s platform and its users.< Out-of-Scope Assets The following are explicitly out of scope for the program: 1. Assets Not Owned by Turo - Cloud providers and infrastructure outside of Turo’s ownership. - Google resources and assets. 2. Internal Systems - Non-production environments (development, test instances) 3. User-Generated Content - Issues related to content posted by hosts (e.g., reviews, images, or listings). 4. Other - Denial of Service (DoS) or Distributed Denial of Service (DDoS) testing. - Automated scans or brute-force attacks that may disrupt Turo services. Accepted Vulnerability Types The following vulnerability types are considered in-scope for the program: - Authentication and Authorization Issues - Broken authentication - Session management flaws - Missing or improper authorization controls - API Security Issues - Insecure API endpoints - Improper input/output validation - Exposure of sensitive data - Web Security Vulnerabilities - Cross-Site Scripting (XSS) - SQL Injection (SQLi) - Cross-Site Request Forgery (CSRF) - Server-Side Request Forgery (SSRF) - Directory traversal - Other OWASP vulnerabilities - Mobile Application Security - Insecure data storage - Hardcoded secrets or credentials or tokens with evidence of significant risk - Insecure communication (e.g., lack of TLS/SSL) - Sensitive Data Exposure - Leaking personally identifiable information (PII) or financial data - Improper access to user accounts or data - Security Misconfigurations - Default credentials, unnecessary permissions, or misconfigured settings - Hardcoded secrets or credentials or tokens with evidence of significant risk or exploitation to Turo - Unpatched software or vulnerable libraries - Business Logic Flaws - Flaws in the flow of transactions or platform logic that could lead to exploitation Out-of-Scope Vulnerability Types The following vulnerability types are considered out of scope: - Low-Impact or Informational Issues - Rate-limiting or account lockout issues (without evidence of significant risk) - Brute-force issues on non-authentication endpoints - Known Issues or Best Practices - Issues related to outdated browsers or unsupported platforms - Previously known vulnerable libraries without a working Proof of Concept. - Use of third-party libraries or frameworks (unless a direct impact to Turo is demonstrated) - Hard-coded credentials or tokens without evidence of significant risk or exploitation. - Missing best practices in SSL/TLS configuration. - Missing HTTP security headers (e.g., HSTS, CSP) without demonstrable impact - Missing best practices in Content Security Policy. - Missing HttpOnly or Secure flags on cookies - Spam and Phishing Reports - Phishing reports, unless originating from Turo-owned domains. - Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.) - The following issues are considered out of scope: - Clickjacking on pages with no sensitive actions - Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions. - Attacks requiring MITM or physical access to a user's device. - Comma Separated Values (CSV) injection without demonstrating a vulnerability. - Any activity that could lead to the disruption of our service (DoS). - Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS - Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version] - Software version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors). - Public Zero-day vulnerabilities that have had an official patch for less than 1 month will be awarded on a case by case basis. - Tabnabbing - Open redirect - unless an additional security impact can be demonstrated - Issues that require unlikely user interaction Rules of Engagement To ensure responsible testing and to avoid disruption, all participants must adhere to the following rules: Do Not: - Create fake or dummy user accounts on turo.com - Create fake or dummy or fraudulent vehicle listings on turo.com - Attempt Denial of Service (DoS/DDoS) attacks. - Test on non-production environments. - Access or modify user data without explicit consent. - Leak, disclose, or exploit any vulnerabilities beyond Turo's disclosure process. Do: - If you want to create fake or dummy user/account to test different flows, create a dummy account on turo.xyz with following naming convention . Delete the account/user created after completing your test. - Name Convention : hackerone-* - Report vulnerabilities promptly with detailed information (proof-of-concept, screenshots, videos, impact, evidence of risk information etc.). - Consider adding the following to the report - Attack scenario / exploitability - Security impact and risk of the bug - Use test accounts for research. - Abide by all applicable laws and regulations. Reporting To submit a vulnerability report: - Submit a report using HackerOne Account - Include a detailed description of the vulnerability, affected assets, Risk and Impact to the assets and steps to reproduce. - Provide any relevant logs, screenshots, or proof-of-concept code. Once you submit your report our HackerOne triage team will check for the report validity, duplicate checks and reach out if additional information is needed. Safe Harbor Turo is committed to working with ethical security researchers in good faith. If you adhere to this policy and responsibly disclose vulnerabilities, Turo will: - Not initiate legal action against you. - Work collaboratively to address the issue promptly. If legal action is initiated by a third party against you as a result of your participation in our bug bounty program, and you have sufficiently complied with our bug bounty policy, we will take reasonable steps to make it known that your actions were conducted in compliance with this policy.