
Finnair Vulnerability Disclosure
External Program
Submit bugs directly to this organization


External Program
Submit bugs directly to this organization
Finnair looks forward to working with the security community to find vulnerabilities in order to keep our businesses and customers safe.
This program adheres to Gold Standard Safe Harbor.
Finnair will make a best effort to meet the following response targets for hackers participating in our program:
| Type of Response | Target in business days |
|---|---|
| First Response | 2 days |
| Time to Triage | 2 days |
| Time to Resolution | depends on severity and complexity |
We'll try to keep you informed about our progress throughout the process.
Researchers should add headers to requests such as:
When reporting vulnerabilities, please consider (1) attack scenario / exploitability, and (2) security impact of the bug. The following issues are considered out of scope:
Thank you for helping keep Finnair and our users safe!