trust,by construction.
Every safety, quality and security record isolated where the data lives, an audit trail you cannot bypass, and an AI that proposes but never decides. One URL for your security team, instead of another questionnaire.
The database has the last word.
One database, every operator separated. If any layer fails, the next still holds, and the deepest layer is the database itself, not app-code filtering.
AI proposes. Humans decide.
The first question a security team asks is whether the AI can change a safety record. It cannot, not on its own and not through the API. Workflow stage and sign-off are reserved for people.
Every write waits for a person. When the AI wants to change a record it stops at a one-click approval card. Nothing is written until someone accepts it.
Unsure output is held back. A low-confidence suggestion, or one outside your taxonomy, is queued for a human. It is never silently written into a safety record.
Your data never trains a model. Tenant data is not used to improve our AI for anyone else. Ever.
Reporters stay protected.
ICAO Annex 19 protection is built in, and it holds through the queue, notifications, partner sharing and the copilot.
Anonymous and confidential intake. In those modes the identity is dropped at write time, unrecoverable by design, not encrypted and held.
Protection tiers with named clearance. Protected, restricted or confidential, opened only by a role allowlist plus explicitly granted clearance.
The protection holds through the AI. A report you are not cleared for is simply not there, even if you ask the copilot.
Lessons travel, reporters do not. A closed occurrence becomes a de-identified bulletin: names, tail numbers and dates scrubbed, a person approves it.
Canada. Encrypted. Yours.
Every operator record in one Canadian region, encrypted at rest and in transit, backed up to the minute, exportable any time.
Canadian residency. Every operator record, database and file storage, in one region (ca-central-1). No stored data at the edge.
Encrypted at rest. AES-256 on the database and on every stored file. Secrets are hashed, shown in full once at create.
Encrypted in transit. TLS 1.3 edge to origin, strict transport security, denial-of-service protection at the network edge.
Recovery to the minute. Point-in-time recovery with a recovery point of one minute or less, and a recovery time under an hour.
Named sub-processor register. Every service that touches your data is listed by category, region and role, vendor names and agreements linked.
Export on demand. Trigger a full export any time, records and the audit log, as JSON, CSV, Parquet or PDF. No lock-in, no ticket.
Open, and governed.
Sign in the way your identity provider works, connect your systems and an AI assistant, and never lose a governance check along the way.
Single sign-on and SAML. Sign in with Google, Microsoft or Okta, or your SAML provider. Single sign-on can be required for the whole operator.
SCIM provisioning. Joiners and leavers created and removed automatically from your directory, no manual list to keep.
Passkeys and MFA. Phishing-resistant passkeys (Touch ID, Windows Hello, hardware keys) or authenticator codes, with admin reset.
Session governance. Each user sees active sessions and last sign-ins, and can sign out everywhere in one click.
Signed webhooks. Every webhook is signed so the receiver can verify it, and every destination is checked against a safe-egress blocklist.
One governed path. The API, the AI connector and the agent connector run the exact same checks as the screen. Automation moves data, only a person signs off.
Built for the regulator's notebook.
The discipline a regulator expects, enforced by the system and proven on a live cluster, not left to good intentions.
A trail you cannot bypass. Every change writes an audit entry in the same transaction as the change itself. Tamper-evident, with a self-serve viewer and export.
Closure that cannot be faked. A degraded barrier needs a linked action, the record cannot close until it passes an effectiveness check, and residual risk needs a two-person co-signed waiver.
SOC 2 Type 2, in preparation. We are running our readiness work. We do not claim a certificate we do not hold, the controls stand on their own, by construction.
Built for the regulators. Designed to support FAA Part 5, EASA Part-ORO, Transport Canada CAR 705 and ICAO Annex 19 audits, proven on a live cluster.
Hand this to your team. We cover the rest live.
For your security team: the one-pager. For procurement: the Buyer's Guide.
The answers hold up in the open. The next leg is the experience: demo to production, with the design partner cohort.