Federal Aviation Administration · Vulnerability Disclosure

Faa Vulnerability Disclosure

Vulnerability disclosure

Federal Aviation Administration runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

TravelUnited StatesAviationAirportsGovernmentRegulatorOpen DataAirspaceDronesAeronautical Information
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
vulnerabilitydisclosure@faa.gov

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-28'
method: searched
probe: true
source: https://www.faa.gov/web_policies/vulnerability_disclosure_policy
policy:
- https://www.faa.gov/web_policies/vulnerability_disclosure_policy
contact:
- vulnerabilitydisclosure@faa.gov
security_txt: false
bug_bounty: false
summary: >-
  The FAA publishes a formal agency Vulnerability Disclosure Policy under its web
  policies, in line with CISA Binding Operational Directive 20-01 for federal
  civilian agencies. It covers all public-facing FAA systems and services — which
  includes the api.faa.gov developer portal and the external-api.faa.gov /
  external.apic4e.faa.gov API gateways. There is no bug bounty and no HackerOne,
  Bugcrowd or Intigriti program: reports go directly to the FAA by email. No RFC
  9116 /.well-known/security.txt is published on any FAA host, so the policy is
  discoverable only as a human-readable web page.
terms:
  safe_harbor: >-
    Good-faith research conducted under the policy is considered authorized; the
    FAA states it will work with the researcher, will not recommend or pursue legal
    action, and will make the authorization known if a third party initiates legal
    action.
  scope: All public-facing FAA systems and services.
  scope_question_contact: vulnerabilitydisclosure@faa.gov
  disclosure_embargo_days: 90
  use_of_reports: >-
    Defensive purposes only — to mitigate or remediate vulnerabilities. Findings that
    affect other users of a product or service, not solely the FAA, may be shared with
    the Cybersecurity and Infrastructure Security Agency (CISA).
  prohibited:
  - Testing systems outside the published scope
  - Physical testing of facilities or resources
  - Social engineering
  - Unsolicited electronic mail to FAA users, including phishing
  - Denial of Service or resource-exhaustion attacks
  - Introducing malicious software
  - Testing that could degrade, impair, disrupt or disable FAA systems
  - Testing third-party applications, websites or services that integrate with FAA systems
  - Deleting, altering, sharing, retaining or destroying FAA data
  - Using an exploit to exfiltrate data, establish command-line access, establish persistence, or pivot
  required:
  - Notify the FAA immediately on discovering a real or potential security issue
  - Stop testing on encountering sensitive data or a potential aviation safety or security hazard
  - Purge stored FAA sensitive data immediately after reporting
  - Allow the agency a minimum of 90 days to resolve before public disclosure
  - Do not submit a high volume of low-quality reports
evidence:
- source: https://www.faa.gov/web_policies/vulnerability_disclosure_policy
  kind: vulnerability-disclosure-policy
  status: 200
  keywords: [vulnerability disclosure, authorized research, safe harbor, 90 days, CISA]
- source: https://www.faa.gov/.well-known/security.txt
  kind: security.txt
  status: 404
  note: not published

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/faa-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.