Security

Security at AFID.

AFID is built as institutional infrastructure and secured to match. This page summarizes how the platform, and the people who use it, are protected. More detailed documentation is available to customers and prospects on request.

By design

A small surface, on purpose

AFID is read-only research infrastructure. Customers query data we publish; they do not upload their own datasets, models, or documents into the platform. A large share of the usual security risk simply does not exist here, because there is little of a customer's own data to expose.

The data itself is drawn from published primary sources: audited financial statements, rate schedules, FAA records, and public bond disclosures. It carries no material non-public information. The only personal data we hold is the business contact details of named users, handled by a dedicated identity provider.

Access

Controlled and accountable

Access is invite-only. Every account is provisioned by AFID; there is no self-service sign-up. Authentication is delegated to a specialist identity provider, so AFID never stores or handles raw passwords. Multi-factor authentication is supported, and enterprise single sign-on is available on request.

Every request to the platform is verified on the server before any data is returned, and that check fails closed: when in doubt, access is denied rather than granted.

Documents

Every source opens through a secure, logged gate

Source documents open one at a time, through links that are unique to an account and expire within minutes. There are no permanent public links and no bulk download. Every document access is recorded with the account, the document, and the time, so access is always attributable and unusual patterns are visible.

Encryption

Encrypted in transit and at rest

All traffic is encrypted in transit with modern TLS, with no unencrypted access path. Data is encrypted at rest in managed storage. Application secrets live only on the server and are never shipped to the browser.

Resilience

Recoverable by construction

Data is published as immutable, versioned snapshots. Recovery is a matter of pointing back to a known-good version, and the application redeploys from source in minutes. There are no customer-managed servers to fail or fall behind on patching.

Infrastructure

Certified providers underneath

AFID runs on established cloud providers that maintain their own independent security certifications, so the platform inherits hardened, audited infrastructure. A SOC 2 Type II program for AFID itself is underway.

Our subprocessors

Clerk · authentication and identity · United States · SOC 2 Type II
Vercel · application hosting · United States · SOC 2 Type II
Cloudflare · storage and content delivery · United States · SOC 2 Type II, ISO 27001
Anthropic · AI-assisted answering · United States · SOC 2 Type II · inputs are not used to train models
Working with you

Ready for your security review

We complete vendor security questionnaires, offer a Data Processing Agreement, and commit contractually to notifying affected customers of a confirmed data breach within 72 hours. More detailed security documentation, including architecture detail, is available to customers and prospects on request, under NDA where appropriate.

Security questions and disclosures: security@afidaviation.com.

Request institutional access

AFID is licensed to bond desks, airports and authorities, and advisory firms. Tell us where to reach you and we'll set up a walkthrough with your team.

Institutional licensing only · no self-serve accounts · demos use illustrative data