generated: '2026-07-28' method: searched probe: true source: https://www.faa.gov/web_policies/vulnerability_disclosure_policy policy: - https://www.faa.gov/web_policies/vulnerability_disclosure_policy contact: - vulnerabilitydisclosure@faa.gov security_txt: false bug_bounty: false summary: >- The FAA publishes a formal agency Vulnerability Disclosure Policy under its web policies, in line with CISA Binding Operational Directive 20-01 for federal civilian agencies. It covers all public-facing FAA systems and services — which includes the api.faa.gov developer portal and the external-api.faa.gov / external.apic4e.faa.gov API gateways. There is no bug bounty and no HackerOne, Bugcrowd or Intigriti program: reports go directly to the FAA by email. No RFC 9116 /.well-known/security.txt is published on any FAA host, so the policy is discoverable only as a human-readable web page. terms: safe_harbor: >- Good-faith research conducted under the policy is considered authorized; the FAA states it will work with the researcher, will not recommend or pursue legal action, and will make the authorization known if a third party initiates legal action. scope: All public-facing FAA systems and services. scope_question_contact: vulnerabilitydisclosure@faa.gov disclosure_embargo_days: 90 use_of_reports: >- Defensive purposes only — to mitigate or remediate vulnerabilities. Findings that affect other users of a product or service, not solely the FAA, may be shared with the Cybersecurity and Infrastructure Security Agency (CISA). prohibited: - Testing systems outside the published scope - Physical testing of facilities or resources - Social engineering - Unsolicited electronic mail to FAA users, including phishing - Denial of Service or resource-exhaustion attacks - Introducing malicious software - Testing that could degrade, impair, disrupt or disable FAA systems - Testing third-party applications, websites or services that integrate with FAA systems - Deleting, altering, sharing, retaining or destroying FAA data - Using an exploit to exfiltrate data, establish command-line access, establish persistence, or pivot required: - Notify the FAA immediately on discovering a real or potential security issue - Stop testing on encountering sensitive data or a potential aviation safety or security hazard - Purge stored FAA sensitive data immediately after reporting - Allow the agency a minimum of 90 days to resolve before public disclosure - Do not submit a high volume of low-quality reports evidence: - source: https://www.faa.gov/web_policies/vulnerability_disclosure_policy kind: vulnerability-disclosure-policy status: 200 keywords: [vulnerability disclosure, authorized research, safe harbor, 90 days, CISA] - source: https://www.faa.gov/.well-known/security.txt kind: security.txt status: 404 note: not published