Three levels
Baseline security
Cloudflare for network protection and DDoS mitigation, Google IAM for identity and access management, AWS Backup for automated recovery and Bitwarden for credential management.
Advanced security
On-premise and private cloud deployments for airlines that require full control over their data environment. ISO 27001 certification is in progress, with audit logging built into the platform.
Military-grade security
Regular third-party penetration testing and independent security audits, including one conducted with Tesla. Infrastructure is protected by CrowdStrike Falcon.
Cybersecurity features
Dedicated VPC + region
Customer data is hosted in a specific AWS region, for example the UAE, within isolated VPCs using separate databases, IAM and policies.
Role-based access control
Three levels: admins create and edit users, members create and edit data, agents have limited access.
Audit logging
Every edit, including flight weights and AWB fields, is logged with a timestamp and user ID for 30 days.
Backup and disaster recovery
7-day daily backups with multi-region storage, allowing full system recovery after failure, loss or breach.
Incident response plan
Predefined procedures for breaches and incidents, including partner notification and recovery timelines.
Vendor risk management
Regular reviews of third-party tools such as Clerk and AWS for compliance and security posture.
GDPR compliance
Manual data requests and deletion for EU privacy compliance: DSRs, consent, export and removal.
Encryption in transit
All user input, including AWBs and cargo information, is encrypted with TLS 1.2+ between browser and backend.
Encryption at rest
All cargo data (AWBs, flights, weights) is encrypted with AES-256 in our databases.
SOC 2 Type II
SOC 2 Type II certification is in progress via Vanta.
ISO 27001
Certification is underway, with the audit logging the standard requires already built into the platform.