Loading this page.
Printed from dollarloanz.com/security/report. Dollar Loans LLC d/b/a Dollar Loanz.
Skip to contentLoading this page.
Loading this page.
Coordinated disclosure
A published policy, real response times, and a safe-harbor commitment that does not depend on whether we enjoy the finding.
Where to send it
Reports go to the address above. We have not set up a separate security inbox, because an unmonitored one is worse than none. Put the subject tag below on it and it skips the general queue.
Subject line:[SECURITY] your one-line summary
The machine-readable version of this policy is at /.well-known/security.txt, as RFC 9116 expects.
Our side of it
With clocks on it, because “we will respond promptly” is what a researcher reads just before deciding to publish on their own schedule.
We acknowledge your report
Within 2 business days
We tell you whether we can reproduce it
Within 5 business days
We give you a remediation plan with dates
Within 10 business days
We agree a public disclosure date with you
Within 90 days, sooner where we can
Safe harbor
About rewards
Scope
The out-of-scope list is not there to make findings inadmissible. It is there because those particular activities hurt customers rather than us.
Short, and all four are about somebody other than us.
A report we can act on
A well-structured report gets triaged sooner. Here is the shape we work from — copy it, fill it in, send it.
A report template, so you don’t have to invent one
Summary
One sentence: what an attacker can do that they should not be able to.
Affected surface
URL or endpoint. In scope for this policy: dollarloanz.com and www.dollarloanz.com.
Steps to reproduce
1.
2.
3.
What you saw
The response, the data, the state change. Redact anything that is not yours.
Impact
Who is harmed, and how badly. Be plain about severity — we will be.
Anything that would help us fix it faster
A proof of concept, a suggested fix, the commit you think caused it.
How you would like to be credited, if at all
Name, handle, or "no credit please".If you land in real customer data by accident, stop and tell us — that alone is a valid report and we will treat it as one. And if you would rather report something without leaving a name, that is fine too: send it from anywhere and we will still fix it. See what we hold in the first place on the security page.
Policy effective from
This contact is valid until
Credits
The Acknowledgments field in our security.txt points here, so this had better be a page that actually credits people rather than one that talks about crediting them.
Nobody yet — the list starts empty and says so
No vulnerability has been reported to us. That is not a boast: this site has not been independently tested, and an empty credits list on a young company means nobody has looked, not that there is nothing to find. Be the first name on it.
Read the policy and report somethingA name goes on this list only with the reporter’s explicit consent and only once the issue is fixed, and the summary never carries enough detail to reproduce anything. If you would rather not be named, say so and you will not be — it changes nothing about how we handle the report.
If you think somebody is impersonating us, or something on your account looks wrong, say so and a person will pick it up.
Registration status
Texas credit access business registration: not yet issued
Check our registration status with the Office of Consumer Credit CommissionerRegulator
Office of Consumer Credit Commissioner
2601 North Lamar Boulevard, Austin, TX 78705
Consumer helpline (800) 538-1579
$2,000 to $50,000. The amount depends on the vehicle and your application. Full fee schedule at /occc. These disclosures are effective September 14, 2026.