Security at AFID.
AFID is built as institutional infrastructure and secured to match. This page summarizes how the platform, and the people who use it, are protected. More detailed documentation is available to customers and prospects on request.
A small surface, on purpose
AFID is read-only research infrastructure. Customers query data we publish; they do not upload their own datasets, models, or documents into the platform. A large share of the usual security risk simply does not exist here, because there is little of a customer's own data to expose.
The data itself is drawn from published primary sources: audited financial statements, rate schedules, FAA records, and public bond disclosures. It carries no material non-public information. The only personal data we hold is the business contact details of named users, handled by a dedicated identity provider.
Controlled and accountable
Access is invite-only. Every account is provisioned by AFID; there is no self-service sign-up. Authentication is delegated to a specialist identity provider, so AFID never stores or handles raw passwords. Multi-factor authentication is supported, and enterprise single sign-on is available on request.
Every request to the platform is verified on the server before any data is returned, and that check fails closed: when in doubt, access is denied rather than granted.
Every source opens through a secure, logged gate
Source documents open one at a time, through links that are unique to an account and expire within minutes. There are no permanent public links and no bulk download. Every document access is recorded with the account, the document, and the time, so access is always attributable and unusual patterns are visible.
Encrypted in transit and at rest
All traffic is encrypted in transit with modern TLS, with no unencrypted access path. Data is encrypted at rest in managed storage. Application secrets live only on the server and are never shipped to the browser.
Recoverable by construction
Data is published as immutable, versioned snapshots. Recovery is a matter of pointing back to a known-good version, and the application redeploys from source in minutes. There are no customer-managed servers to fail or fall behind on patching.
Certified providers underneath
AFID runs on established cloud providers that maintain their own independent security certifications, so the platform inherits hardened, audited infrastructure. A SOC 2 Type II program for AFID itself is underway.
Our subprocessors
Ready for your security review
We complete vendor security questionnaires, offer a Data Processing Agreement, and commit contractually to notifying affected customers of a confirmed data breach within 72 hours. More detailed security documentation, including architecture detail, is available to customers and prospects on request, under NDA where appropriate.
Security questions and disclosures: security@afidaviation.com.