Security and Responsible Disclosure
Last reviewed: July 31, 2026
Product security
AsFlown is architected for strict data custody. Raw recorder files remain under operator control. Our decoding algorithms preserve cryptographic SHA-256 fingerprints to ensure data lineage and verification against airframer documentation.
Responsible disclosure
AsFlown Technologies values security researchers who help protect our infrastructure. If you discover a potential vulnerability in our website or endpoints, please report it to our team with reproducible steps.
Scope & Guidelines
In-scope systems include asflown.com and related public API endpoints. Prohibited testing methods include denial of service (DoS), automated spam, social engineering, or unauthorized access to customer data.
Report a concern
To submit a security finding or vulnerability report, contact contact@asflown.com.