Reporting a security problem

Last updated: 4 September 2026

If you have found a way to make Dronetrake do something that should not be possible, we want to hear it from you before someone else finds it. This page says where to write, what happens next, and what we guarantee you.

Write to: security@dronetrake.com · security.txt

How to report

An email in English or Italian to the address above. Tell us what you found, how to reproduce it step by step, what impact you think it has, and how we can get back to you. If you have a screenshot or a network request that shows it, attach it. No form, no account needed.

What we do, and when

We reply within two working days to say the report arrived and who is looking at it. Within five working days we tell you whether we reproduced it and how we classify it. From there we keep you posted until it is closed, and at the end we tell you what we changed. If something is serious we handle it straight away, without waiting for those deadlines.

What matters most to us

Dronetrake exists to produce evidence that has to hold up in front of third parties: flights, recordings, signed checklists and seals, linked in a chain. If you have found a way to alter, backdate, or silently remove any of these, that is the report we want first. Right behind it come access to another organisation's data, authentication bypass, and code execution on our systems.

What we ask you not to do

Do not look at data that is not yours: the moment you realise you can reach it, stop and write to us. No load testing and no service disruption. No phishing or social engineering against the people who work with us or against our customers. No physical access to premises. No mass automated scanning that degrades the service for someone who is flying right then.

What we guarantee you

If you act in good faith and stay within this page, we consider your research authorised: we will not take legal action against you and will not ask others to. If anyone challenges your activity, we will say you were within the terms we published. We only ask that you do not disclose the problem until it is fixed, and that you agree the timing with us.

We do not pay bounties

We have no bounty programme and we promise no money: we would rather tell you up front than afterwards. What we can do is actually answer you, fix it quickly, and thank you publicly on this page if you want. If you prefer to stay anonymous, you stay anonymous.

Scope

This covers dronetrake.com and its subdomains, the platform, the mobile apps, and the Sync agent. Out of scope are the third-party services we use for payments, streaming and mail: those have their own channels, and a report gets there faster. If you are unsure about scope, write anyway: we would rather have an out-of-scope report than one that never reaches us.