Security & compliance

Aviation-grade controls, end to end.

Every request is authenticated, authorized, scoped to a tenant and recorded.

Authentication

Argon2 password hashes, OTP verification, optional TOTP 2FA, lockout on repeated failures.

Authorization

Granular RBAC: Super Admin, Admin, Dispatcher, Customer User. Permissions mapped to roles.

Tenant isolation

All operator data scoped by operator_id. Customers never see other tenants.

Audit logging

Immutable user/action/entity log for SOC 2 and regulatory review.

Session security

Refresh tokens with 30-minute TTL, IP and user-agent binding, revocable.

Notification center

License expiry, subscription renewal and compliance warnings.

Compliance certifications

  • SOC 2 Type II
  • ISO 27001:2022
  • GDPR & UK-GDPR
  • ICAO Doc 4444 alignment
  • EASA AOC operator readiness

Subscription enforcement

Three layers prevent accidental feature exposure across managed and self-managed customers.

  1. 01 Backend middleware blocks restricted endpoints
  2. 02 Frontend hides or disables locked modules
  3. 03 Audit log records every access attempt