Responsible Disclosure Policy
HeliEFB takes the security of our software seriously. We welcome reports from security researchers and the public that help us keep our users — including HEMS, SAR, law enforcement, military, and offshore helicopter operators — safe.
Reporting a Vulnerability
Please report suspected security vulnerabilities to:
If you need to send sensitive details, encrypt your report using our PGP key, published at /.well-known/security-pgp-key.txt.
Please include, where possible:
- A description of the vulnerability and its potential impact
- Steps to reproduce, or a proof of concept
- The affected component, version, or URL
- Your assessment of severity
What to Expect
- Acknowledgement: within 3 business days of your report
- Initial assessment: within 10 business days
- Resolution timeline: communicated once the issue is triaged, based on severity
- We will keep you informed of progress and notify you when the issue is resolved
For vulnerabilities that fall under our obligations as a manufacturer under the EU Cyber Resilience Act (CRA), we follow the required reporting timelines to ENISA and affected users in addition to our own remediation process.
Scope
This policy covers:
- The HeliEFB iPad application
- The HeliEFB web backend and associated APIs
- Infrastructure directly operated by HeliEFB in support of these services
Out of scope:
- Third-party services we integrate with but do not operate
- Social engineering, physical security, or denial-of-service testing
Safe Harbor
We will not pursue legal action against researchers who:
- Make a good-faith effort to avoid privacy violations, data destruction, and service disruption
- Report vulnerabilities promptly and do not exploit them beyond what is necessary to demonstrate the issue
- Do not publicly disclose the issue before we have had a reasonable opportunity to address it (coordinated disclosure)
Separate Channels
- General support: support@heliefb.com
- Data protection inquiries: dataprotection@heliefb.com
Thank you for helping keep HeliEFB and its users safe.
