Built for the people who share the airplane—and the responsibility. See how it works

Security at AirplaneHQ

Protect the shared operating picture.

Security is a combination of product controls, production configuration, disciplined operations, and responsible choices by every partnership member.

01

Identity and access

Access starts with an authenticated account and active partnership membership, then narrows by role and aircraft.

  • Adaptive password hashing
  • Hashed, expiring API tokens
  • CSRF protection for browser forms
  • Role- and aircraft-aware authorization
02

Tenant boundaries

Operational records carry partnership context and service-layer authorization is designed to prevent cross-partnership access.

  • Partnership-scoped queries
  • Opaque public identifiers
  • Document visibility controls
  • History-preserving membership lifecycle
03

Data protection

Production deployments should use HTTPS, private object storage, encryption, narrow cloud permissions, and protected secrets.

  • Secure and HTTP-only cookie options
  • Private S3 storage support
  • Server-side object encryption
  • Time-limited signed downloads
04

Application safeguards

The application validates input, limits request size, protects storage keys, and returns defensive browser headers.

  • Upload request limit
  • Opaque randomized storage names
  • Path traversal protection
  • Security and privacy response headers
05

Reliability and recovery

Health checks, database recovery, storage versioning, monitoring, and tested restore procedures form the intended production baseline.

  • Liveness and readiness endpoints
  • Database connection validation
  • Recoverable archive workflows
  • Document and logbook activity history
06

Review and improvement

Security requires recurring tests, dependency review, incident learning, and independent assessment as the service grows.

  • Automated authorization tests
  • Deployment verification
  • Production-readiness checklist
  • Responsible disclosure process

Shared responsibility

What partnership administrators control.

Membership

Verify invitation email addresses, minimize owners, review aircraft access, and offboard promptly.

Data choices

Upload only authorized records, choose document visibility carefully, and minimize personal information.

Account hygiene

Use unique passwords, protect email and devices, and never share tokens or private calendar URLs.

Independent controls

Maintain required source records, backup expectations, and safety-critical procedures outside notification delivery.

Report a vulnerability

Help us investigate responsibly.

Include the affected area, impact, safe reproduction steps, and your contact information. Do not include credentials or unrelated customer data.