Skip to content

Compliance & records

The records the CAA asks for, kept as a by-product of the day

Written for a Head of Training, a CFI or an accountable manager: what FlyerOS records, what it produces on demand, and what it refuses to let through. Each capability below is marked live, preview or planned.

Answers by regulation

A dedicated page for each area an inspection turns on, what the rule asks, and how FlyerOS holds it.

Training records that stand up

Live
ORA.GEN.220ORA.ATO.120

Every lesson is recorded with what was covered, the grade, and who signed it, and, crucially, who can prove they signed it. A record is signed by an identified person, and that signature is bound to the record rather than to a printout that can be swapped later.

A correction never overwrites. An amendment is appended, carrying who made it, when and why, so the original stands beside the correction and the history is intact. That is what reliable traceability and protection from alteration mean in practice, and it is retained for the period a training organisation is expected to keep records after a course completes.

Knowing who did what, inside your own school

Live

The transparency a Head of Training actually cares about is internal: who signed that lesson, who changed a grade after the fact, who deferred that defect, who moved a booking the morning of a skill test. Every record carries its own history in place, created by whom, every amendment, who made it, when and why, append-only, so the original is never lost and a correction sits visibly beside what it corrected.

It is scoped by role: an instructor sees their assigned students, an accountable manager sees everything. In most schools this lives in a paper folder, a shared drive and somebody’s memory. Here it is a by-product of running the day, maintained by nobody.

Theoretical knowledge and examinations

Live
Recommendation validitySRG2155

FlyerOS records the recommendation validity clock, the eighteen-month window that runs from the end of the calendar month of first attempt, along with attempts per subject, the number of sittings, and the pass mark, so a student’s theoretical-knowledge position is a fact rather than a reconstruction.

It records examination paper custody and the reporting a school owes, so the SRG2155 return is assembled from records you are already keeping. It does not sit the exam or guarantee an outcome; it keeps the record straight.

Instructor qualifications and privileges

Live

Licences, ratings, medicals and instructor privileges are structured data with expiry dates, not a wall of certificate scans. The schedule reads them: it refuses to book an instructor for something they are not currently authorised or current to do, and it says why.

Instructor flight time limitations

Live
ORA.ATO.130(d)Appendix 1

Duty and flight-hour limits are modelled as rolling windows and checked when a booking is made, not discovered afterwards. A booking that would breach a limit is refused with the reason, so the limitation shapes the roster rather than being reconciled after the month closes.

Aircraft airworthiness and the schedule

Live

An open defect, a directive or an expiring ARC makes an aircraft unbookable in the calendar the moment it is recorded. A scheduled check coming due is forecast forward and flagged against each booking with the tolerance in the programme applied: an aircraft that would be flown beyond its limits on the fourteenth is refused for the fourteenth, and one still inside tolerance is flagged as a decision, because eligibility is evaluated for the time the flight is scheduled for, not the moment it was booked.

Occurrence and safety reporting

Planned

On the roadmap, not built yet: confidential occurrence reporting, a hazard and risk register, and corrective actions tracked to closure, with the tighter access controls safety data deserves, and an ECCAIRS-ready export. Until it ships, keep running your SMS in your current tools. Telling us how you run it shapes what we build.

Your inspection

Live

At a standardisation visit or a continuation audit an inspector asks for specific evidence about specific people, aircraft and dates. FlyerOS assembles it as an evidence pack, scoped to what was asked, date-filtered, read-only and expiring, from the records the day already produced, rather than a fortnight of reconstruction.

This section is meant to be useful to your school whether or not you ever buy FlyerOS: it is a plain description of what a UK inspection actually asks for.

DTO obligations

Live

The annual internal review and the annual activity report are assembled from records a declared training organisation is already keeping day to day, not written from memory once a year against a deadline.

Where your records live, and who can see them

The questions an accountable manager actually asks, answered plainly.

Where is our data held?
On managed infrastructure in the UK/EU region, with encryption in transit and at rest. Data-residency options are set at the organisation level.
Who at FlyerOS can see our students’ records, and is it logged?
Support and operations staff may access your data to run and support the service, and every such access is written into your own audit trail, you can see it. There is no hidden access.
Can another school ever see our data?
No. Every record is scoped to one organisation and access derives from an authenticated membership of that organisation. A member of one school cannot read another’s records.
What happens to our records if we stop using FlyerOS?
You export everything, training records, flight records, documents, in usable formats, at no cost, including after you leave. Your regulator expects you to hold those records and we do not stand between you and them.
How long are records kept?
For as long as your account is active and thereafter as you direct, reconciled with the retention a training organisation is subject to. Deletion and return follow the data processing agreement.
What happens if you have an outage, or go out of business?
There is a published service level agreement with an availability commitment and service credits, and your right to export your own data at any time means your records never depend on us being here.
Technical detail for your IT reviewer

Strict tenant isolation (row-level, on every tenant-owned table), capability-based authorization evaluated server-side from an authenticated membership, an append-only audit trail for privileged actions, server-side-only secrets, and GDPR-oriented controller/processor controls.

The full architecture write-up lives on the security overview.

FlyerOS helps you operate your approved or declared procedures. It does not itself confer certification or approval; every regulatory rule is modelled with its source, jurisdiction and effective date so you stay in control.

The commercial terms behind this, data processing agreement, service level agreement and privacy policy, are all published.

See how your records would look in an inspection