<!-- Public mirror of the repository's SECURITY.md (prompt 19 / W-11). Every claim here must stay true and in lockstep with SECURITY.md β€” update both together at the 6-month incident-response review. Repo-only links (runbooks, incidents/) are deliberately described rather than linked: the repositories are private. -->

Security

Aviation Expert GPT is operated by ZEXOR DIGITAL, LLC. This page covers the web application at https://aviation-expert-gpt.com, its backend API, and the iOS and Android apps (com.zexordigital.aviationexpertgpt).

Reporting a vulnerability

Email contact@aviation-expert-gpt.com with SECURITY in the subject line.

Machine-readable version: /.well-known/security.txt

Please include:

  • what you found and where (URL, endpoint, app screen, or build number)
  • the steps to reproduce it
  • what an attacker could do with it
  • any logs, requests or screenshots that help

If the report contains sensitive material and you would prefer an encrypted channel, say so in a first message without the details and we will arrange one.

What to expect

  • Acknowledgement: within 3 business days
  • First assessment: within 10 business days
  • Fix timeline: severity-dependent; we will tell you what we find and keep you updated

This is a small, independently operated product β€” there is no security team and no 24/7 rota. We will be straight with you about timelines rather than promise ones we cannot meet.

We do not run a paid bug-bounty programme and cannot offer monetary rewards. We are glad to credit you publicly for a valid report if you would like that.

Scope

In scope

  • aviation-expert-gpt.com and its subdomains
  • the backend API, including the /api, /back-end and /android-back-end route trees
  • the iOS and Android applications

Out of scope

  • our third-party providers' own infrastructure β€” report those to the provider directly (see our subprocessor list)
  • findings from automated scanners with no demonstrated impact
  • missing hardening headers or best-practice deviations with no exploitable consequence
  • social engineering, physical attacks, or anything targeting our staff or users
  • denial of service, volumetric testing, and automated scanning at a rate that degrades service for real users

Testing rules

Please:

  • use your own account and your own data β€” never access, modify or retain another user's data
  • stop as soon as you have confirmed a vulnerability; do not pivot, escalate further, or exfiltrate
  • do not run destructive tests, mass automation, or load/stress testing against production
  • do not test payment flows with real charges β€” tell us what you found and we will reproduce it
  • give us reasonable time to fix an issue before disclosing it publicly

Testing that follows these rules, in good faith, is authorised and we will not pursue action over it. Testing that breaks them β€” accessing other people's data, degrading the service, or holding findings for leverage β€” is not.

What we hold

So you can judge the impact of what you find: user accounts (name, email, date of birth, country), pilot and mechanic licence numbers, flight and maintenance logbooks, AI chat history, and user-uploaded documents.

Payment card data is never handled by our servers β€” web checkout runs on Stripe's hosted Checkout and mobile purchases run through the App Store and Google Play via RevenueCat.

How we respond to incidents

We maintain a written incident-response plan covering all three platforms. It defines severity levels, first-response procedures, containment levers, evidence handling, and our external notification obligations β€” including the 72-hour regulatory clock for a personal-data breach. Every incident that required containment gets a written postmortem, and the build fails if an incident is recorded without one.

Our commitment to notify affected users and regulators is stated in the Privacy Policy.


Last reviewed: 2026-08-12

Aviation Expert GPT AI-Powered Intelligence