Skip to main content
CitadelAero

Legal

Acceptable Use Policy

Version 1.0 · Last updated 18 August 2026

This policy sets out what you may and may not do with our services. It is incorporated into the CitadelAero Master Services Agreement at clause 11.1, and it binds every customer and every authorised user.

1. Who and what this covers

This policy applies to all use of the CitadelAero SMS Platform, Regulatory AI Intelligence, the demonstration environments, the billing portal, and citadelaero.com and its subdomains (together, the "Services").

It binds the customer and every authorised user the customer permits to access the Services. A customer is responsible for its authorised users' compliance.

Terms defined in the Master Services Agreement have the same meaning here.

2. The general rule

Use the Services lawfully, for your own aviation safety, compliance and operational purposes, and in a way that does not harm other customers, other users, or CitadelAero.

Everything in section 3 follows from that rule. Where a situation is not expressly covered, this general rule governs.

3. What you must not do

3.1 Unlawful and harmful use

You must not:

  • use the Services for any unlawful purpose, or in breach of any applicable law or regulation;
  • upload, transmit or store content that is unlawful, defamatory, fraudulent, obscene, or that infringes the intellectual property or privacy rights of any person;
  • use the Services to harass, threaten or discriminate against any person;
  • misrepresent your identity, your authority to act, or your affiliation with any organisation; or
  • use the Services in a way that creates an unacceptable operational safety risk.

3.2 Security and integrity

You must not:

  • attempt to gain unauthorised access to any part of the Services, to any other customer's data or environment, or to our underlying infrastructure;
  • circumvent, disable or interfere with any access control, authentication, encryption, usage limit or other technical restriction;
  • interfere with or disrupt the integrity, performance or security of the Services, or the data of any other customer;
  • introduce malware, viruses or other harmful code;
  • share, sell or transfer login credentials, or permit any person other than an authorised user to access the Services using your credentials; or
  • probe, scan or test the vulnerability of the Services except as permitted by section 5.

3.3 Commercial restrictions

You must not:

  • sublicense, resell, rent, or otherwise make the Services available to a third party who is not an authorised user, without our prior written consent;
  • use automated scripts, robots, crawlers or scraping tools to access the Services or extract data, except through an API we have expressly provided for that purpose;
  • copy, reproduce or redistribute any regulatory corpus, knowledge base, template or other CitadelAero content made available through the Services, other than for your own internal use;
  • use the Services to build, train or assist in building a competing product or service; or
  • publish benchmarking or comparative performance results about the Services without our prior written consent.

3.4 Just culture

Occurrence reporting depends on reporters trusting that what they report will not be used against them. That trust is a regulatory requirement and a safety mechanism, not a courtesy.

You must not:

  • use the Services, or any data held in them, in a way that is inconsistent with the just culture principles underpinning Regulation (EU) 376/2014 and its UK equivalent;
  • use occurrence report data in connection with disciplinary, civil, criminal or administrative proceedings against a reporter, except in cases of gross negligence or wilful misconduct as defined under applicable law;
  • attempt to identify a reporter who has reported confidentially, or use the Services' access controls or audit records for that purpose; or
  • configure access to occurrence report data in a way that defeats the protections you are required to provide as a reporting entity.

3.5 Data you put into the Services

You must not:

  • submit personal data you do not have a lawful basis to process, or that you are not entitled to disclose to us as your processor;
  • submit special category personal data beyond what is genuinely necessary for aviation safety management, without having assessed your own lawful basis for doing so;
  • submit flight data monitoring material to any of the Services without first satisfying your own gatekeeper and de-identification arrangements;
  • submit real occurrence data, personal data or production data to a demonstration environment; or
  • submit content to the Services that you are contractually or legally prohibited from disclosing to a third party.

3.6 Regulatory AI Intelligence

Additional rules apply to Regulatory AI Intelligence, including rules about reliance on generated output and the distinction between grounded regulatory answers and general assistance. They are set out in the AI Use Policy and in Schedule B of the Master Services Agreement, and form part of this policy.

In summary, and without limiting the AI Use Policy: generated output is a draft for a competent person to review, never a compliance decision, and must not be relied on without verification against the source material.

4. Fair and reasonable use

Where a plan states a limit — on aircraft, users, seats, documents or usage — that limit is the measure of fair use. You must not attempt to exceed it by technical means, by creating additional accounts, or by sharing a single account between people.

Where a plan does not state a numerical limit, use must remain reasonable and consistent with normal operation by an organisation of your size. We will discuss any concern with you before taking action under section 6.

5. Security research and vulnerability disclosure

We welcome reports of suspected security vulnerabilities. Report them to security@citadelaero.com with enough detail to reproduce the issue.

If you are testing in good faith, keep within these boundaries: test only against your own account or environment; do not access, modify, exfiltrate or retain any other customer's data; do not degrade the Services for others; do not run denial-of-service, brute-force or high-volume automated testing; and give us a reasonable opportunity to respond before disclosing publicly.

We will not treat testing that stays within those boundaries as a breach of this policy, and will not pursue action in respect of it. Testing outside them is a breach of section 3.2.

6. Enforcement

We may investigate any suspected breach of this policy and take the action we reasonably consider appropriate, which may include:

  • contacting you to discuss the matter and agree a remedy;
  • removing or disabling access to specific content;
  • suspending an individual authorised user's access;
  • suspending the customer's access under clause 11.3 of the Master Services Agreement; or
  • terminating the affected Order Form under clause 16.5 of that Agreement.

We will ordinarily contact you first and give a reasonable opportunity to put matters right. We will act without prior notice only where we reasonably believe a serious breach has occurred or is ongoing, or where notice would risk harm to other customers, to safety, or to the security of the Services. Where we act without prior notice, we will notify you as soon as reasonably practicable and restore access promptly once the breach is resolved.

Suspension under this policy is separate from restriction for non-payment. Restriction for non-payment preserves the ability to read records and submit a safety report; suspension under this policy does not.

7. Reporting a problem

8. Changes to this policy

We may update this policy from time to time. Where a change materially reduces what you are permitted to do, we will give not less than thirty (30) days' notice, in accordance with clause 11.4 of the Master Services Agreement. The current version is always published on this page.

© JLEC Limited t/a CitadelAero · citadelaero.com · Version 1.0