Responsible Disclosure Policy

HeliEFB takes the security of our software seriously. We welcome reports from security researchers and the public that help us keep our users — including HEMS, SAR, law enforcement, military, and offshore helicopter operators — safe.

Reporting a Vulnerability

Please report suspected security vulnerabilities to:

security@heliefb.com

If you need to send sensitive details, encrypt your report using our PGP key, published at /.well-known/security-pgp-key.txt.

Please include, where possible:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce, or a proof of concept
  • The affected component, version, or URL
  • Your assessment of severity

What to Expect

  • Acknowledgement: within 3 business days of your report
  • Initial assessment: within 10 business days
  • Resolution timeline: communicated once the issue is triaged, based on severity
  • We will keep you informed of progress and notify you when the issue is resolved

For vulnerabilities that fall under our obligations as a manufacturer under the EU Cyber Resilience Act (CRA), we follow the required reporting timelines to ENISA and affected users in addition to our own remediation process.

Scope

This policy covers:

  • The HeliEFB iPad application
  • The HeliEFB web backend and associated APIs
  • Infrastructure directly operated by HeliEFB in support of these services

Out of scope:

  • Third-party services we integrate with but do not operate
  • Social engineering, physical security, or denial-of-service testing

Safe Harbor

We will not pursue legal action against researchers who:

  • Make a good-faith effort to avoid privacy violations, data destruction, and service disruption
  • Report vulnerabilities promptly and do not exploit them beyond what is necessary to demonstrate the issue
  • Do not publicly disclose the issue before we have had a reasonable opportunity to address it (coordinated disclosure)

Separate Channels

Thank you for helping keep HeliEFB and its users safe.