Security & your data
Your records are yours, kept separate, and kept safe.
You are trusting FlyerOS with your school’s operational records. Here is what that means in plain terms, and, further down, the technical detail your IT or procurement reviewer will ask for.
Your records are yours
Export everything, training records, flight records and documents, in usable formats, any time, at no cost, including after you leave. Your data is never stuck here.
No hidden access
Our team can open your data to support you, and every time we do it is written into your own audit trail, so you can see it. Nothing happens behind the glass.
Held in the UK and EU
Your school’s records are held in the UK/EU region, encrypted on the way in and while they sit at rest. Where a supplier processes data outside the UK, we cover it with approved safeguards.
Nothing gets quietly changed
Training, safety and compliance records keep their full history. A correction is added beside the original, never over it, so you can always see who changed what, and when.
Safety reports stay confidential
The safety module protects a reporter’s identity and can restrict sensitive cases to the people who need them.
If something goes wrong, you hear it from us
We publish an availability commitment with service credits, and on an incident we tell affected schools what we know and what we are doing. Because you can export any time, your records never depend on us being here.
For your IT reviewer
The technical detail, for the person who has to sign it off.
The questions a procurement or data-protection assessment asks, answered plainly, and marked Planned where something is not in place today rather than left silent.
Tenant isolation
Every tenant-owned table carries an organisation key with row-level security. Automated tests assert that a member of one organisation cannot read or write another’s records, through the UI, API, crafted IDs, file URLs or exports.
Capability-based authorization
Access is evaluated server-side from an authenticated membership: identity → membership → scope → permission → entitlement → record → state. Client-supplied role or organisation IDs are never trusted.
No self-elevation
Role and permission changes require high privilege, are server-only, and are written to an immutable before/after audit. A user cannot escalate their own role by editing a request payload.
Encryption
Data is encrypted in transit (TLS) and at rest by the infrastructure provider. Provider credentials, webhook secrets and privileged database clients live only in server and worker contexts; the browser never receives a service key.
Immutable audit & evidence
Privileged and security actions append to an immutable audit trail. Training, safety and compliance records use versioned amendments rather than silent overwrites, and support access is logged into the customer’s own trail.
Files, scoped and signed
Objects are namespaced by organisation, served through short-lived signed URLs, and access is checked, never derived from mere knowledge of an object key.
Data residency
Your school’s records are held in the UK/EU region. Where a sub-processor processes limited data outside the UK, the transfer is covered by the UK IDTA or SCCs with a transfer risk assessment. Region choice for groups with specific residency requirements is available on enterprise agreements.
Sub-processors
A small set of sub-processors: cloud hosting, database and file storage, email delivery, error monitoring, and the integrations a school switches on such as weather, registry lookups and accounting. The itemised current list, with each one’s location and transfer safeguard, is provided with the DPA, and we notify customers before it changes.
Backup & recovery
PlannedThe database is continuously backed up with point-in-time recovery by our infrastructure provider. Restore procedures are documented; scheduled restore-testing is on the roadmap.
Retention & deletion
Records are retained while your account is active and thereafter as you direct, reconciled with the regulatory retention a training organisation must observe. Deletion and export requests are honoured under the DPA.
Incident response & notification
We monitor the service and, on a security or availability incident, notify affected customers with what we know and what we are doing, then follow up with a summary. Formal notification timeframes are set out in the DPA.
UK GDPR position
The school is the controller and FlyerOS the processor for hosted data, with retention classes, legal-hold exceptions and data-subject request workflows. Read-auditing applies to special-category data.
Security practices
Built to recognised security practices: strict tenant isolation, least privilege, and encryption in transit and at rest. We are glad to complete a security questionnaire as part of procurement.
Penetration testing
PlannedWe run internal security review and automated checks. An independent third-party penetration test is planned ahead of general availability, with a summary available to customers under NDA.
The data processing agreement and the service level agreement are both published, and the sub-processor list is provided with the DPA.
FlyerOS is designed to help schools operate their approved or declared procedures. It does not itself confer regulatory compliance, certification or approval.