
Security
Protect the account. Report the vulnerability responsibly.
Drivver combines account controls, monitoring, restricted access and security testing. No system can be guaranteed completely secure.
Account protection
Never share an OTP or password. Keep the device locked and updated. Review unfamiliar activity. Report account takeover, SIM/device loss or suspicious support contact.
Secure my accountWhat belongs in support: Account compromise, suspicious login, payment abuse or impersonation involving a user account goes to Account Security/Support — not the researcher channel below.
Responsible disclosure.
Research scope
In-scope domains/apps, excluded systems, prohibited testing, privacy protection, service-disruption rules and data handling will be published here once the programme is approved.
How to report
Secure email/form; reproducible description; affected asset/version; impact; proof with minimal data; researcher contact where offered.
Response: Drivver acknowledges, triages, validates, remediates and communicates according to severity and programme terms. No bounty is promised unless an approved programme states it.
security.txt
Our machine-readable security policy is published at /.well-known/security.txt, with contact, policy and expiry information.