DOCUMENT NOTICE
PRODUCTION NOTICE: This exact version was approved for production and made effective on August 1, 2026 by Jaime E. Fuentes II under TT-LGL-000P, TT-LGL-000Q, and TT-LGL-000R. This Policy is active for the in-scope systems described in Section 8. Initial reports may be sent to security@truckertech.com, and a separate secure-transfer method may be arranged after initial contact. Missing operational details will be updated when the relevant information becomes available. This Policy does not create a bug-bounty program, payment promise, response-time commitment, or authorization to access another person’s account, data, or systems.
TT-SEC-012
Purpose
TruckerTech welcomes good-faith reports that help protect users, customers, Partners, and the Platform.
TT-SEC-012
Authorized Research
Research must be limited to in-scope TruckerTech-controlled public systems, accounts the researcher owns, and data the researcher is expressly authorized to use. Researchers must minimize access and impact; use the least data necessary; stop upon encountering another person’s personal, confidential, or restricted data; avoid persistence; avoid retaining unnecessary copies; promptly report the issue; and provide TruckerTech a reasonable opportunity to investigate and remediate before public disclosure.
TT-SEC-012
Prohibited Activity
Do not perform denial-of-service or resource-exhaustion testing; social engineering; phishing; physical intrusion; malware deployment; destructive testing; credential stuffing; mass account creation; spam; automated scanning that materially degrades service; access to another person’s data; alteration or deletion of data; extortion; or testing of third-party services outside TruckerTech’s control.
TT-SEC-012
Reporting
Reports should be sent to security@truckertech.com and should include the affected asset, a concise description, reproduction steps, observed impact, researcher contact information, and whether any data was accessed. Do not send passwords, authentication secrets, identity documents, payment information, personal information, live exploit payloads, or other sensitive evidence through ordinary email. Send a minimal initial report, and TruckerTech may provide a separate secure-transfer method when additional evidence is needed.
TT-SEC-012
Safe-Harbor Intent
To the extent permitted by law and within TruckerTech’s control, TruckerTech does not intend to initiate legal action against a researcher for good-faith security research that complies with this Policy, avoids privacy and operational harm, stays within the stated scope, promptly reports the issue, and follows reasonable coordination instructions. This statement does not bind third parties, immunize unlawful conduct, authorize access to another person’s data, excuse violations unrelated to the research, waive contractual rights of others, or prevent TruckerTech from acting to protect users, customers, systems, or evidence.
TT-SEC-012
Handling
TruckerTech will evaluate reports according to apparent risk, available evidence, affected systems and users, provider involvement, and operational priorities. TruckerTech may request additional information, coordinate validation and remediation, or refer an issue to an affected provider. No bounty, payment, response time, remediation time, public credit, or disclosure date is promised unless separately stated in writing.
TT-SEC-012
Confidentiality
Researchers must protect nonpublic information and coordinate public disclosure. TruckerTech may share a report with affected providers, customers, professional advisers, insurers, or authorities as reasonably necessary to investigate, protect people and systems, comply with law, preserve evidence, or remediate the issue. Public disclosure should not occur until TruckerTech has had a reasonable opportunity to investigate and address the issue.
TT-SEC-012
Scope
In scope are TruckerTech-controlled public production websites, applications, and APIs that expressly link to this Policy or are expressly confirmed in writing by TruckerTech. Out of scope are Preview, staging, local, development, employee-only, administrative, customer-controlled, third-party, Ecosystem Partner, provider, telecommunications, payment, email, identity, social-media, and physical systems unless TruckerTech expressly includes them. Testing must use the researcher’s own account and data or a TruckerTech-authorized test account and must respect ordinary rate limits and access controls.