Product security
We focus on protecting account access, case records, documents, payment state, and role boundaries.
- Authentication and session protections
- Role and tenant isolation
- Non-destructive vulnerability review
My Traffic Case
Report suspected vulnerabilities affecting MyTrafficCase accounts, cases, documents, payments, or communications. We prioritize issues that could affect access, isolation, sensitive data, or payment state.
Target acknowledgement for well-formed submissions.
We do not store full card numbers or CVV codes.
We focus on protecting account access, case records, documents, payment state, and role boundaries.
Case and document workflows are designed to keep sensitive traffic-ticket information attached to the right matter.
Card payments are handled through validated payment providers instead of storing card data in MyTrafficCase.
Well-formed reports are prioritized by impact and coordinated directly with the reporter when validation is needed.
How to report
Email security@mytrafficcase.com with a concise report. Authorized testing is limited to your own accounts, test data, and non-destructive verification.
Testing boundaries
Do not attempt password attacks, denial-of-service testing, persistence, social engineering, mass scraping, or access to real customer data. Reports involving account access, tenant isolation, document exposure, payment state changes, authentication bypass, sensitive data leakage, or production secret exposure receive priority.
Payment compliance
Payments are processed through PCI DSS validated payment providers. Stripe-powered payment flows use Stripe, a PCI Service Provider Level 1. We do not store full card numbers or CVV codes. This statement describes the payment-provider model and is not a claim that MyTrafficCase has completed its own PCI certification or SAQ-A.
Learn more about Stripe security and compliance posture directly from Stripe.
Stripe security page