Security
FuelOracle welcomes reports of security problems in the service and its apps. This page explains how to report one and how to test without harming anyone.
How to report
Email security@fueloracle.com.au with:
- what the problem is and what an attacker could do with it
- where it is: the URL, API endpoint, MCP tool, or app and version
- the steps to reproduce it
You will get an acknowledgement within 5 business days. We will keep you updated while we work on a fix and let you know when it has shipped. Please keep the details private until then.
In scope
- https://fueloracle.app, including its API
- The FuelOracle MCP server at https://fueloracle.app/mcp and its sign-in
- The FuelOracle apps for iOS and Android
- https://fueloracle.com.au
Fuel price data comes from state government schemes. Report problems with that data to the scheme that publishes it.
Testing safely
- Use your own account, or a test account you create. Do not access, change or delete anyone else's data. If you reach another person's data by accident, stop and tell us.
- Do not run denial-of-service tests, load tests or automated scanners that send large volumes of traffic.
- Do not use social engineering, phishing or physical attacks against FuelOracle or its users.
- Do not put a vulnerability to use beyond what is needed to show it exists.
Rewards
FuelOracle does not run a paid bug bounty. We are glad to credit you when a fix ships, if you would like that.