Safety & Security
Road Less Traveled is built to make the drive the best part of your day — which only works if you arrive safely and can trust what the app does with your information. Here is what we do on both fronts.
Safety on the road
- Nothing to tap while you're moving. RLT never asks you a question while the car is moving. The data-sharing question and the short questions after a drive appear only when you're stopped or have arrived.
- Never routed toward schools. RLT never steers you toward K-12 schools. When it looks for more interesting roads, any new option that passes more schools than the fastest route is dropped, and schools are never used as scenic stops. Colleges and universities are not affected.
- Your time, your choice. The Adventure slider is a hard limit on how much extra time a route may add. RLT never encourages speeding, racing or challenges — travel times come from normal road speeds.
- Never stranded. If RLT's own routing is ever unavailable, the app still gives you a plain route home instead of an error.
- The road has the final say. RLT's routes are suggestions. Always follow road signs, traffic laws, closures and conditions, and keep your attention on driving.
Security of your data
- Collect less. No account, name, email or contacts. See the Privacy Policy for exactly what is collected and why.
- Encrypted in transit. Everything between the app and RLT's servers travels over encrypted (HTTPS) connections.
- Servers that aren't open to the internet. RLT's services accept connections only through an encrypted tunnel; they can't be reached directly. Administrative access requires a cryptographic key.
- Locked doors inside. RLT's data services require the app's access key, and the operations dashboard requires a login.
- Kept up to date. Servers apply security updates automatically, sit behind a firewall, and automatically block repeated failed logins.
- Drive data, once sharing begins. Drive sharing is opt-in and is being built now. When it starts, shared drives are labeled with a random ID instead of anything about you, the start and end of every drive are removed on your phone before upload, backups are encrypted before they leave our server, and Delete my drive data in the app removes your drives from our servers and backups.
Vulnerability disclosure policy
Peregrinator Motus LLC welcomes reports from security researchers and the public. If you believe you've found a vulnerability, privacy issue, exposed data or other security problem in any of our systems, we want to hear from you. This policy explains how to report it, what we expect, and what you can expect from us.
Systems in scope
- the Road Less Traveled iPhone app;
api.peregrinatormotus.comandrouting.peregrinatormotus.com;- this website,
peregrinatormotus.com.
Out of scope
- systems we don't own or operate — including Cloudflare, Apple, HERE Technologies, weather services and government road-data services. Please report issues in those to their owners.
- denial-of-service testing, automated flooding or load testing;
- social engineering, phishing, or physical attacks against people, vehicles or property.
Our commitments
- We'll acknowledge your report within 5 business days.
- We'll give you an initial assessment — whether we can reproduce it and how serious it is — within 14 days.
- We'll keep you informed of progress at least every 30 days until it's resolved, and work to fix confirmed problems promptly, within our operational constraints.
- With your permission, we'll credit you publicly once the issue is fixed.
- We'll extend Safe Harbor (below) to research that follows this policy.
We don't run a paid bug bounty program at this time.
Our expectations
In participating in good faith, we ask that you:
- follow this policy and any other relevant agreements — if anything conflicts, this policy prevails;
- report any vulnerability you've discovered promptly;
- avoid violating the privacy of others, disrupting our systems, destroying data, or harming people's use of the app;
- use only the official channel below to discuss vulnerability information with us;
- give us reasonable time to resolve the issue before disclosing it publicly — until it's fixed, or 90 days from your report, whichever comes first;
- test only in-scope systems, and respect the out-of-scope ones;
- if a vulnerability gives unintended access to data, access only the minimum needed to demonstrate it, and stop testing and report immediately if you encounter anyone else's data — such as location or drive data;
- interact only with your own app installation and data, or with explicit permission from its owner; and
- don't engage in extortion.
Official channel
Email hello@peregrinatormotus.com with "Security" in the subject line. Include what you found, where, and the steps to reproduce it — the more detail, the faster we can triage and fix it.
Safe Harbor
When conducting vulnerability research according to this policy, we consider research conducted under this policy to be:
- authorized concerning any applicable anti-hacking laws, and we will not initiate or support legal action against you for accidental, good-faith violations of this policy;
- authorized concerning any relevant anti-circumvention laws, and we will not bring a claim against you for circumvention of technology controls;
- exempt from restrictions in our Terms of Service and/or Acceptable Use Policy that would interfere with conducting security research, and we waive those restrictions on a limited basis; and
- lawful, helpful to the overall security of the Internet, and conducted in good faith.
You are expected, as always, to comply with all applicable laws. If legal action is initiated by a third party against you and you have complied with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through the official channel before going any further.
Note that the Safe Harbor applies only to legal claims under the control of Peregrinator Motus LLC, and that this policy does not bind independent third parties.
This policy is adapted from the open-source disclose.io templates.
Contact
Peregrinator Motus LLC · hello@peregrinatormotus.com