Introduction
AFL welcomes reports from security researchers and the public about vulnerabilities in our website. This policy explains what you may test, how to report what you find, and what you can expect from us. We run it as a disclosure program, without monetary rewards.
Guidelines
- Tell us about a vulnerability as soon as you find it.
- Avoid privacy violations, harm to other visitors, disruption to our systems, and the destruction or change of data.
- Use an exploit only as far as needed to confirm that a vulnerability exists. Never use one to take or change data, keep access, or move on to other systems, such as the tracking portal or email.
- If you come across personal information or anyone else’s data, stop, tell us, and delete what you have. Never keep, share or use it.
- Give us a reasonable time to fix the issue before you disclose it publicly.
Scope
In scope: the Avery Freight Lines website at https://averyfreight.com and https://www.averyfreight.com, as hosted on Vercel, including its quote and carrier setup forms and the endpoint behind them (/api/quote).
Out of scope: every other system, including any other server that has answered at these addresses, the shipment-tracking portal, email systems, and the services of our providers, such as Vercel, Cloudflare, Microsoft, Proofpoint and Resend, and other addresses that serve this site, such as its vercel.app addresses: test at averyfreight.com. Report issues in those services to their owners.
Test methods outside this policy
- Denial-of-service tests, load tests, high-volume automated scanning, or any testing that degrades the Site for others.
- High-volume or automated submissions of the quote or carrier setup form; each submission reaches our staff.
- Social engineering of AFL staff or partners, such as phishing or phone calls, and physical testing.
- Testing with accounts, data or systems that are not yours.
How to report
Email support@averyfreight.com with “Security report” in the subject line. Please include:
- the page or endpoint affected;
- a description of the vulnerability and its possible impact;
- the steps to reproduce it, with any proof-of-concept, leaving out personal data.
You may report anonymously. Reports in English help us respond fastest. Our security.txt file lists the same contact.
What to expect
When you share your contact details, we aim to acknowledge your report within three business days, confirm whether we can reproduce it, keep you informed while we work on it, and tell you when it is fixed. We keep your name and contact details private unless you give us permission to share them or the law requires us to, and with your permission we are glad to credit you for the discovery.
Questions
Questions about this policy, or about whether a test is in scope, are welcome before you start. See also our Terms of Use.
Security reports and questions:
C-NA Worldwide LLC d/b/a Avery Freight Lines11175 Azusa Ct., Suite 110
Rancho Cucamonga, CA 91730
support@averyfreight.com
(909) 918-5477
