Security & Vulnerability Disclosure
1.Overview
Crossroutes takes the security of rider accounts and data seriously. This page explains how to report a suspected security issue, what happens after you do, and how long app versions stay covered by security fixes.
2.How to report a vulnerability
Email [email protected] - the same address published in machine-readable form at /.well-known/security.txt (RFC 9116). Please include enough detail to reproduce the issue: what you did, what you expected to happen, and what happened instead.
3.What happens after you report
- We aim to acknowledge every genuine report within 24 hours.
- We investigate and confirm the issue, then work on a fix. We don't promise one fixed timeline for every report - severity varies too much for that to be honest - but a confirmed, actively exploitable issue affecting user data takes priority over anything else in progress.
- We'll keep you updated on progress on request, and credit you (with your permission) once a fix ships - or keep you anonymous if you'd rather.
4.Coordinated disclosure
We ask that you give us a reasonable opportunity to investigate and fix a reported issue before disclosing it publicly. In turn: if you report a genuine vulnerability in good faith through the channel above, without accessing, modifying, or extracting other users' data beyond what's strictly needed to demonstrate the issue, we won't pursue legal action against you for that research. This isn't a paid bug-bounty program, but genuine reports are always welcome and taken seriously.
5.Security updates & supported versions
Crossroutes is distributed exclusively through Google Play, which keeps the app updated automatically for the large majority of users. Security fixes are always free of charge. We don't maintain a fixed list of "supported" older versions - the currently published Google Play release is the one we keep secure, and since the app updates itself automatically for almost everyone, being on the latest Play Store version means you already have our current security posture.
6.Security advisories
No vulnerabilities have been publicly disclosed to date. Once a reported vulnerability is fixed, a short, plain-language summary will be added here - what was affected, when it was fixed, and (with permission) credit to whoever found it.
7.Contact
[email protected] - see also /.well-known/security.txt and the app's Privacy Policy.