Federal Aviation Administration · Vulnerability Disclosure

Faa Vulnerability Disclosure

Vulnerability disclosure

Federal Aviation Administration runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

TravelUnited StatesAviationAirportsGovernmentRegulatorOpen DataAirspaceDronesAeronautical Information
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
vulnerabilitydisclosure@faa.gov

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-28'
method: searched
probe: true
source: https://www.faa.gov/web_policies/vulnerability_disclosure_policy
policy:
- https://www.faa.gov/web_policies/vulnerability_disclosure_policy
contact:
- vulnerabilitydisclosure@faa.gov
security_txt: false
bug_bounty: false
summary: >-
  The FAA publishes a formal agency Vulnerability Disclosure Policy under its web
  policies, in line with CISA Binding Operational Directive 20-01 for federal
  civilian agencies. It covers all public-facing FAA systems and services — which
  includes the api.faa.gov developer portal and the external-api.faa.gov /
  external.apic4e.faa.gov API gateways. There is no bug bounty and no HackerOne,
  Bugcrowd or Intigriti program: reports go directly to the FAA by email. No RFC
  9116 /.well-known/security.txt is published on any FAA host, so the policy is
  discoverable only as a human-readable web page.
terms:
  safe_harbor: >-
    Good-faith research conducted under the policy is considered authorized; the
    FAA states it will work with the researcher, will not recommend or pursue legal
    action, and will make the authorization known if a third party initiates legal
    action.
  scope: All public-facing FAA systems and services.
  scope_question_contact: vulnerabilitydisclosure@faa.gov
  disclosure_embargo_days: 90
  use_of_reports: >-
    Defensive purposes only — to mitigate or remediate vulnerabilities. Findings that
    affect other users of a product or service, not solely the FAA, may be shared with
    the Cybersecurity and Infrastructure Security Agency (CISA).
  prohibited:
  - Testing systems outside the published scope
  - Physical testing of facilities or resources
  - Social engineering
  - Unsolicited electronic mail to FAA users, including phishing
  - Denial of Service or resource-exhaustion attacks
  - Introducing malicious software
  - Testing that could degrade, impair, disrupt or disable FAA systems
  - Testing third-party applications, websites or services that integrate with FAA systems
  - Deleting, altering, sharing, retaining or destroying FAA data
  - Using an exploit to exfiltrate data, establish command-line access, establish persistence, or pivot
  required:
  - Notify the FAA immediately on discovering a real or potential security issue
  - Stop testing on encountering sensitive data or a potential aviation safety or security hazard
  - Purge stored FAA sensitive data immediately after reporting
  - Allow the agency a minimum of 90 days to resolve before public disclosure
  - Do not submit a high volume of low-quality reports
evidence:
- source: https://www.faa.gov/web_policies/vulnerability_disclosure_policy
  kind: vulnerability-disclosure-policy
  status: 200
  keywords: [vulnerability disclosure, authorized research, safe harbor, 90 days, CISA]
- source: https://www.faa.gov/.well-known/security.txt
  kind: security.txt
  status: 404
  note: not published