Trust & security
Built for safety-critical aerospace.Secured accordingly.
AeroCert handles certification artifacts, requirements, compliance evidence, and program data that is often ITAR-controlled, often proprietary, and always sensitive. We’ve designed the platform around that reality from day one. This page documents where we are today and what we’re building toward — without hand-waving.
Last updated: April 2026. Contactsecurity@aerospacecert.iowith questions.
Hosting
AWS US
us-east-1, us-west-2
Encryption
AES-256 / TLS 1.3
At rest and in transit
SSO
SAML 2.0
Okta, Entra, Google
SOC 2
Type II
In progress · Q4 2026
01
Data handling & sovereignty
Customer data is stored in the United States, in Amazon Web Services regions us-east-1 and us-west-2. We do not replicate customer data outside the United States.
Data is encrypted at rest with AES-256 and in transit with TLS 1.3. Each customer’s data is isolated at the database level — we do not use shared row-level multi-tenancy for primary data.
Customer-managed encryption keys (CMK via AWS KMS) are on the near-term roadmap for enterprise tier customers.
Backups are encrypted, retained for 30 days, and tested monthly. Customers can export all of their data at any time via the API or on request. Deletion of a customer tenant purges data within 30 days.
02
Access controls
SAML 2.0 SSO is supported on every plan, not gated behind an enterprise tier. We integrate with Okta, Microsoft Entra ID, and Google Workspace. MFA is enforced for all administrative roles.
Role-based access control is modeled on certification roles — program manager, certification engineer, DER/AR, software lead, hardware lead, auditor read-only — not on generic CRUD permissions.
Every access event, configuration change, and artifact modification is logged to an append-only audit trail with retention configurable by the customer.
Internal access to customer data follows least privilege. Engineers do not have standing production access; access is granted just-in-time, time-bound, and logged.
03
ITAR & export compliance
AeroCert’s ITAR registration with the Directorate of Defense Trade Controls is in progress, with a target completion of Q3 2026.
Until registration is complete, we support ITAR-controlled programs only after a customer-specific review. Customers should not upload ITAR-controlled technical data without first contacting us.
Once registered, all customer data will be accessible only by US persons as defined in 22 CFR § 120.62. Our roadmap includes deployment to AWS GovCloud (US) for customers requiring it; target availability is 2027.
For EAR-controlled but non-ITAR data, AeroCert’s standard US-only deployment is appropriate today.
04
Compliance & certifications
We publish our status against each framework, including the ones we haven’t reached yet. Audit reports and evidence are available under NDA on completion.
05
Secure development
All code is peer-reviewed before merge. Dependencies are scanned continuously (Dependabot, Snyk). Static analysis (SAST) runs on every pull request; dynamic analysis (DAST) runs against staging weekly.
Third-party penetration testing is conducted annually by a recognized firm. Summary reports are available to customers under NDA. The most recent test was completed in Q1 2026.
We commit to notifying affected customers of confirmed security incidents within 72 hours of detection, with material updates as investigation proceeds.
06
Reliability & continuity
Our service level objective is 99.9% monthly uptime. Live status, historical incidents, and component-level metrics are published atstatus.aerospacecert.io.
Backups are taken hourly for the active database with point-in-time recovery, and replicated to a second AWS region. Our recovery time objective (RTO) is 4 hours; our recovery point objective (RPO) is 15 minutes.
07
Subprocessors
Every third party that may process customer data, with purpose and region. We notify customers of additions or material changes at least 30 days in advance.
08
Vulnerability disclosure
If you believe you’ve found a security vulnerability in AeroCert, please report it tosecurity@aerospacecert.io. We acknowledge reports within one business day and commit to acting in good faith on legitimate disclosures.
A full security.txt is published at/.well-known/security.txt.
Documents available on request
- · SOC 2 report (under NDA)
- · Penetration test summary
- · DPA template
- · MSA template
- · Subprocessor list
- · Security questionnaire responses