Security and vulnerability disclosure
How the service is protected
- All traffic uses HTTPS (TLS 1.2 or later) with HTTP Strict Transport Security. Plain HTTP requests are redirected to HTTPS.
- The service is fronted by Cloudflare and hosted on Google Cloud in the United States.
- Application routes require sign-in. Access is role-based and scoped to the user's organization and incidents.
- Passwords follow an enforced policy; sign-in is rate-limited; multi-factor authentication (TOTP) is available.
- Session cookies are Secure, HttpOnly, and SameSite=Lax.
- Create, update, and delete actions on agency and incident records are audit-logged.
- The application does not use advertising trackers or third-party analytics.
PDF exports and downloads
PDF forms (for example, ICS-205) are generated on the Comm-Piler server from the saved plan.
The browser receives each file as a standard HTTPS download from api.comm-piler.com
with Content-Type: application/pdf and Content-Disposition: attachment,
using a single-use link that expires after five minutes. No executable files, macros, or browser
extensions are ever downloaded. Spreadsheet (XLSX/CSV) exports are also generated on the server.
Reporting a vulnerability
If you believe you have found a security issue, email [email protected] with the subject line “Security report”. Please include the affected URL, steps to reproduce, and the impact you observed.
- We aim to acknowledge reports within 3 business days.
- Please do not access, modify, or delete data that is not yours, and do not run denial-of-service or social-engineering tests.
- Give us a reasonable time to fix the issue before public disclosure.
- We will not pursue legal action against good-faith research that follows these guidelines.
Machine-readable contact: /.well-known/security.txt.