Report suspected vulnerabilities privately through our security form. Do not publish exploit details, access data that is not yours, disrupt service, or test against another customer's account.
1. Our security approach
FlightSim Control uses layered controls appropriate to a Windows desktop product with an online account and licensing service. These include least-privilege service access, transport encryption, server-side entitlement decisions, protected release delivery, audit events, dependency review, abuse controls, and separation between public configuration and privileged credentials.
We review material findings according to exploitability, affected data, user impact, and whether the issue crosses the local simulator, account, payment, or release boundary.
2. Accounts and entitlement
Authentication is handled through the configured account provider. Subscription and device-entitlement decisions are made by trusted server-side services rather than values supplied by the browser or desktop client. Activation credentials and download links are designed to be scoped, revocable, and short-lived.
3. Desktop and simulator boundary
Routine simulator control is designed to remain on the user's Windows computer. The local bridge communicates with Microsoft Flight Simulator through supported local interfaces. The public website cannot directly issue live aircraft commands. Aircraft-specific capabilities remain gated unless the installed provider and exact command path are detected and supported.
The application does not require users to expose SimConnect, a bridge API, or Windows remote administration to the public internet. Customers should keep those services restricted to the local computer or a trusted private network.
4. Release integrity
Public Windows releases will be made available only after the installer and application binaries pass code-signature verification, malware scanning, clean-machine installation, update, removal, and entitlement checks. Downloads are issued from protected storage through customer-specific, expiring links.
Install FlightSim Control only from flightsimcontrol.com. Do not bypass operating-system signature warnings or use packages shared by third parties.
5. Report a vulnerability
Use the security report form. Include the affected URL, application version, a concise description, reproducible steps, observed impact, and any non-sensitive evidence. Remove credentials, payment data, licence keys, and personal data from screenshots and logs.
If a file is necessary, first submit the written report and wait for a secure transfer method. A support reference will be issued for follow-up.
6. Responsible research
Good-faith research must use accounts and devices you own or are expressly authorised to test. Do not use denial-of-service techniques, social engineering, physical attacks, automated high-volume scanning, persistence, data destruction, privacy invasion, payment fraud, or access beyond the minimum needed to demonstrate the issue.
No reward or safe-harbour programme is promised unless Evolve Orbit agrees to it in writing. We nevertheless welcome careful reports and will not knowingly pursue action merely for a good-faith report that respects these limits and applicable law.
7. What happens next
We acknowledge valid reports, triage severity, preserve relevant evidence, investigate affected components and providers, and communicate material remediation progress where practical. Security fixes may be released without disclosing details that would increase risk to users who have not yet updated.
8. Customer responsibilities
Keep Windows, Microsoft Flight Simulator, aircraft add-ons, FlightSim Control, browsers, and security software current. Protect the email account used to sign in, use device-level access controls, revoke devices no longer under your control, and report suspicious account or licensing activity promptly.