Security

How to report a vulnerability, how we handle your data, and what we commit to.

Responsible disclosure

We welcome reports from security researchers. If you believe you've found a vulnerability in TowGo — the customer app, driver app, fleet dashboard, marketing site, or any TowGo API — please tell us before disclosing publicly.

Our commitments to reporters:

  • We will acknowledge receipt within 3 business days.
  • We will give you a first triage response within 10 business days.
  • We will keep you informed as we work through remediation.
  • We will not pursue legal action against researchers acting in good faith and within this policy.

What we ask from reporters:

  • Do not access, modify, or delete data that isn't yours.
  • Do not degrade service for real users — no load testing, no denial of service.
  • Give us reasonable time to fix before public disclosure. 90 days is our default coordination window.
  • Do not use social engineering, physical access, or attacks against employees.

Report a vulnerability

Email [email protected] with a description of the issue, reproduction steps, and any proof-of-concept you're comfortable sharing. Encrypted mail welcome — PGP key on request.

This form opens your email client with the report pre-filled. For richer submissions, email us directly.

Bug bounty

We do not currently run a paid bug bounty program. We plan to launch one once our platform surface stabilizes. In the meantime, we credit valid reporters in our security acknowledgements (with your permission), and we're happy to send TowGo swag for confirmed findings.

Data handling summary

The full details live in our privacy policy. A quick overview:

  • All traffic between TowGo apps, browsers, and our servers is encrypted in transit over TLS 1.2+.
  • Personal data at rest is stored in encrypted databases at vetted cloud providers.
  • Payment card data is handled by Stripe. TowGo never stores raw card numbers or CVVs.
  • Location data is retained only as long as needed to service tows, resolve disputes, and comply with law.
  • Access to production data is restricted to a small number of engineers on a need-to-know basis, with audit logging.
  • You can request deletion of your account at /delete-account.

Compliance references

TowGo is designed to align with the following standards and regulations. Formal certifications, where they apply, land here as they're completed.

  • PCI DSS — via Stripe as our payment processor. TowGo maintains a SAQ-A scope by never touching raw card data.
  • CCPA / CPRA — California residents can exercise privacy rights through our privacy policy.
  • GDPR — for EU-resident data, where applicable, we honor access and deletion requests.
  • SOC 2 — planned. We'll publish the report when we complete our first observation window.
Related: privacy policy, terms, all policies.