Security
Last updated: 24.08.2026
We take the security of FoxRide and of our users' data seriously. Despite careful development, vulnerabilities can never be fully ruled out. That is why we explicitly welcome responsible reports from security researchers and users: the sooner we learn about an issue, the faster we can fix it.
Reporting a vulnerability
Please report security vulnerabilities confidentially by email and do not disclose them publicly before we have fixed them.
E-Mail: [email protected]
What to include in your report
- Affected component or URL (e.g. app area, website page, API endpoint)
- A description of the vulnerability and its underlying cause, as far as known
- Reproducible steps (screenshots, requests or log excerpts are welcome)
- Potential impact (what could an attacker achieve with it?)
- A way to contact you for follow-up questions
What we commit to
- We confirm receipt of your report within 3 business days.
- We assess the report and get back to you with our evaluation.
- We keep you informed about the progress and completion of the fix.
- On request, we credit you as the finder in our release notes.
What we ask of you
So that we can protect you, please stick to the following rules during your testing:
- Do not exploit a vulnerability beyond what is needed for a proof of concept.
- Do not access, modify or delete other users' data.
- Do not run DoS, spam or social engineering tests and do not disrupt live operations.
- Give us a reasonable period to fix the issue before publishing any details.
As long as you follow these rules and act in good faith, we consider your research authorised and will not take legal action against you.
Scope
In scope
- FoxRide iOS app including the Watch app
- foxride.app (website and user account)
- routes.foxride.app (web route planner)
- The FoxRide API endpoints
Out of scope
- Third-party services we merely integrate (e.g. Apple App Store, Mollie, Nominatim/OpenStreetMap)
- Our social media channels and content hosted there
- Findings without concrete security relevance (e.g. missing best-practice headers with no demonstrable impact)
No bug bounty
FoxRide is a small, independent project. We currently do not offer monetary rewards for reported vulnerabilities. We are, however, sincerely grateful for every responsible report and are happy to credit you as the finder on request.
security.txt
Machine-readable contact information according to RFC 9116 is available at: