Security

Security at WingWrangler

We protect your flight records, student data, and financial information. Here is how we do it.

Our Approach

We look after your data with the same care as aircraft maintenance. We use documented procedures. We inspect regularly. We accept no shortcuts. Aviation needs precision. Security needs it too.

Data Encryption
In Transit TLS for all connections
At Rest AES-256 encryption on all databases
Backups Encrypted snapshots. Recovery to any point in time.
Access Control
Authentication TOTP 2FA. Secure sessions.
Authorization Role-based access control (RBAC)
Sessions Expire after 24 hours. Secure cookies.
Infrastructure
Hosting Providers that comply with SOC 2 Type II
Databases Isolated, encrypted, per-tenant schemas
Edge CDN with WAF and DDoS protection
Tenant Isolation
Org Membership Verified on every request
Financials & PII Scoped to your organization
Logbooks Locked to the signed-in pilot
Security Practices
Every code change gets a peer review
Automated security scans run on every build
We monitor dependencies for known vulnerabilities
Every service checks that you act for your own organization
Internal admin and diagnostic ports are never on the public internet
Error messages and logs do not contain internal details or personal data
Compliance & Certifications
SOC 2 Type II

Roadmap

In Progress
GDPR Compliant

EU data handling

Yes
CCPA Compliant

California privacy

Yes
Aviation Regulator Coverage

Every WingWrangler organization is bound to one civil-aviation regulator (FAA, EASA, CASA, or 7 more). Endorsements, recency rules, retention policies, and exports adapt automatically. We plan EASA Part-IS / ISMS support in Q3–Q4 2026.

View regulator coverage matrix
Data Handling

Data Location

We host your data with providers that comply with SOC 2 Type II. Region-specific residency (EU / UK) is on our roadmap. The region depends on the civil-aviation regulator you select at signup.

Data Isolation

We isolate the data of each organization. We use row-level security and separate schemas. This stops one organization from accessing the data of another organization.

Employee Access

Only essential personnel can access production data. We log all access. We review the logs regularly.

Incident Response

If a security incident affects your data, we do these steps:

  • • We tell affected customers within 24 hours
  • • We send a detailed incident report
  • • We describe the steps we took to fix the problem
  • • We give affected customers suitable remedies
Responsible Disclosure

Did you find a security vulnerability? Tell us. We appreciate responsible disclosure. Report issues to:

[email protected]

Do not disclose vulnerabilities in public until we have had time to fix them. We acknowledge reports within 48 hours. We keep you informed about our progress.

Security Questions?

Do you need security questionnaires, audits, or compliance documentation? Contact us: