Frameworks Holdings LLC believes security is a shared responsibility. We appreciate the efforts of security researchers, developers, customers, and members of the community who help us identify potential vulnerabilities in Army Flight Logbook.
If you believe you have discovered a security issue, we encourage you to report it responsibly so that we can investigate and address it as quickly as possible.
Our goal is to work collaboratively with researchers while protecting our users and maintaining the security and availability of our services.
Scope
This policy applies to vulnerabilities affecting services owned and operated by Frameworks Holdings LLC, including:
Army Flight Logbook iOS App
Army Flight Logbook Android App
Army Flight Logbook Web
Company Management Dashboard
Public APIs
Authentication Services
Public websites
Supporting cloud infrastructure under our control
Third-party services such as Google Cloud, Firebase, Stripe, Apple, Google Play, Intercom, and Acumbamail are governed by their own vulnerability disclosure programs.
How to Report a Security Issue
If you discover a potential vulnerability, please email our security team.
Security Contact
Email: [email protected]
Please include as much information as possible, including:
A clear description of the issue.
Steps to reproduce the issue.
The affected platform (iOS, Android, Web, etc.).
Screenshots or screen recordings, if applicable.
Proof-of-concept code, if available.
The potential impact of the issue.
Your contact information for follow-up questions.
The more information you provide, the more quickly we can investigate.
What We Ask of Researchers
To help protect our users, we ask that you:
Act in good faith.
Avoid violating the privacy of other users.
Do not access, modify, or delete data that does not belong to you.
Do not intentionally disrupt or degrade our services.
Do not exploit vulnerabilities beyond what is necessary to demonstrate the issue.
Do not publicly disclose vulnerabilities until we have had a reasonable opportunity to investigate and address them.
Follow all applicable laws while conducting security research.
Safe Harbor
Frameworks Holdings LLC supports responsible security research conducted in good faith.
If you:
Follow this Responsible Disclosure Policy,
Avoid intentionally harming users or our services,
Respect user privacy,
Report vulnerabilities directly to us,
we will not pursue legal action against you solely for your good-faith security research.
This statement does not authorize activities that violate applicable laws, intentionally disrupt services, or access information belonging to others without authorization.
What Is In Scope
Examples of issues we are interested in include:
Authentication bypasses
Authorization vulnerabilities
Privilege escalation
Remote code execution
SQL injection
Cross-Site Scripting (XSS)
Cross-Site Request Forgery (CSRF)
Server-Side Request Forgery (SSRF)
Insecure Direct Object References (IDOR)
Sensitive data exposure
API security issues
Broken access controls
Security misconfigurations
Session management vulnerabilities
Cryptographic weaknesses
File upload vulnerabilities
Security issues affecting Company Management
Security issues affecting cloud infrastructure under our control
Out of Scope
The following generally fall outside the scope of this policy:
Missing HTTP security headers without demonstrated impact.
Clickjacking on pages without sensitive functionality.
Best-practice recommendations without an exploitable vulnerability.
Vulnerabilities affecting unsupported browsers or operating systems.
Social engineering attacks against employees or users.
Physical attacks.
Denial-of-service testing.
Automated vulnerability scans that generate excessive traffic.
Spam or phishing campaigns.
Issues affecting third-party services outside our control.
Reports based solely on outdated software versions without a demonstrable security impact.
Response Process
When a report is received, our general process is:
Acknowledge receipt of the report.
Review the information provided.
Validate the reported issue.
Assess the severity and potential impact.
Develop and test a fix.
Deploy the remediation.
Notify the reporter when appropriate.
Review the incident for lessons learned and process improvements.
Response times may vary depending on the complexity and severity of the reported issue.
Severity Assessment
We prioritize reports based on factors such as:
Impact on users.
Likelihood of exploitation.
Exposure of sensitive information.
Ability to bypass authentication or authorization.
Operational risk.
Availability of mitigations.
Critical issues receive the highest priority.
Recognition
At this time, Frameworks Holdings LLC does not operate a public bug bounty program.
However, we greatly appreciate responsible disclosures that help improve the security of Army Flight Logbook. With your permission, we may acknowledge your contribution in future security updates or release notes.
Confidentiality
Information related to reported vulnerabilities is treated as confidential during the investigation and remediation process.
We ask researchers to refrain from publicly disclosing vulnerabilities until we have had a reasonable opportunity to investigate and address the issue.
Continuous Improvement
Security is an ongoing effort.
Every responsible disclosure helps us improve Army Flight Logbook, strengthen our security program, and better protect the aviation community we serve.
We sincerely appreciate the time, expertise, and professionalism of those who work with us to improve the security of our platform.
