Pacific Dirt Roads
Security & Responsible Disclosure
How we protect the booking service and how security researchers can report a suspected vulnerability responsibly.
Last updated: August 25, 2026
Our approach
Security is part of how we operate the booking website and restricted backoffice. Current safeguards include HTTPS, access-controlled staff sessions, role checks, server-side input and pricing validation, request rate limits, audit events, private signed access to booking evidence, and a public reservation flow that never requests payment card details.
We limit access to operational data to authorized staff and use established infrastructure providers for hosting, data storage, authentication, and email. Safeguards are reviewed as the service changes, but no online system can guarantee absolute security.
Report a vulnerability
Email a suspected security issue to info@quadtourscostarica.com. Use the subject “Security report — Pacific Dirt Roads” and do not include active credentials, payment card numbers, or unnecessary personal information.
A useful report includes:
- The affected URL or feature and the date you observed the issue.
- Clear reproduction steps and the impact you believe is possible.
- Minimal, non-sensitive evidence such as sanitized screenshots or request details.
- A safe way to contact you for questions or remediation coordination.
Automated security tools can also discover our machine-readable security.txt contact record.
Scope
This disclosure process covers the production website at https://www.quadtourscostarica.com and first-party code served from that origin. Third-party platforms such as Supabase, Vercel, Resend, WhatsApp, and Google Maps are governed by their own disclosure programs and are outside our testing authorization.
Responsible testing rules
- Use the minimum testing necessary to demonstrate the issue and avoid accessing real customer records.
- Stop immediately and report the issue if you encounter personal, financial, or confidential information.
- Do not change, delete, download, retain, or disclose data that does not belong to you.
- Do not use denial-of-service tests, credential stuffing, automated high-volume scanning, malware, spam, social engineering, physical attacks, or tests that create real charges or disrupt bookings.
- Do not publicly disclose an unresolved issue before coordinating a reasonable remediation period with us.
- Follow applicable law. This policy does not authorize access or activity that would otherwise be unlawful.
What to expect
We will review good-faith reports, assess their impact, and prioritize remediation based on risk. When you provide contact information, we may ask for clarification and share meaningful status updates. Please allow time to investigate and deploy a safe fix before discussing the report publicly.
This is a coordinated-disclosure channel, not a bug-bounty program. We do not currently offer monetary rewards, and submission does not create a contract or guarantee recognition.
Security or privacy incident
If you are a customer and believe a booking communication, payment request, or personal detail has been misused, contact us promptly at info@quadtourscostarica.com or call +506 2101-5736. Include your booking reference, but never send full card details by email or messaging.