Responsible disclosure

Help us protect the vehicle network.

If you believe you have found a security vulnerability in OID, report it privately and give us a reasonable opportunity to investigate before sharing details publicly.

How to report

Email admin@onsellr.com with “OID security report” in the subject. Include the affected URL or component, the observed behaviour, reproducible steps, likely impact and a safe way to contact you. Do not send credentials, identity documents or unrelated personal information.

Research boundaries

Use your own accounts and fabricated or explicitly authorised OIDs. Do not access another person's data, alter a real vehicle record, submit fraudulent evidence, disrupt availability, run denial-of-service testing, send spam, use social engineering or test third-party providers without their permission.

What happens next

We will acknowledge a credible report as soon as practical, triage its severity, preserve relevant evidence and provide progress updates where possible. Remediation timing depends on impact, exploitability and the safety of the proposed fix.

Current scope

The public website, authenticated OID workflows, versioned APIs, agent runtime boundaries, webhook verification and exposed OID-owned infrastructure are in scope. Findings that exist only in a third-party service should be reported to that provider unless the issue is caused by OID configuration or integration.

No public secrets

Never include API keys, database credentials, session cookies or sensitive evidence in a public issue. If a secret is exposed, stop testing, report it immediately and do not retain or reuse it.