Features Pricing Demo Contact Security About Sign in Request access

Security You Can Trust

Your permit data and compliance records are protected with enterprise-grade infrastructure and industry-standard security practices.

✓ SOC 2 Type II Certified Infrastructure ✓ TLS 1.3 Encryption ✓ Data Isolation ✓ Zero AI Data Retention

How We Protect Your Data

Built with security as a first principle, not an afterthought

🔒

Encryption in Transit

All data is encrypted using TLS 1.3 the same standard used by major banks. Your permit documents are never transmitted in plain text.

🏢

Complete Data Isolation

Your organization's data is completely isolated from other customers. Cross-tenant data access is architecturally impossible by design.

🤖

Zero AI Data Retention

We use Anthropic's enterprise API with a zero data retention policy. Your permits are never stored by Anthropic or used to train AI models.

👤

Secure Authentication

Passwords are hashed with bcrypt never stored in plain text. JWT tokens expire automatically and are invalidated on logout.

🛡️

DDoS Protection

Our cloud infrastructure provides automatic DDoS mitigation at the network level, protecting your access to AirComply at all times.

🔐

Role-Based Access

Granular user roles ensure team members only access what they need. Admin, manager, and read-only roles are fully supported.

Our Infrastructure

Built on trusted, certified platforms

🚂

Enterprise Cloud Infrastructure

AirComply runs on SOC 2 Type II certified cloud infrastructure provided by Railway. Our hosting layer provides automatic TLS, DDoS protection, infrastructure monitoring, and high availability. Your data stays in US-based data centers.

SOC 2 Type II Certified Infrastructure US Data Centers
🧠

Anthropic Claude AI

AI analysis is powered by Anthropic's Claude via their enterprise API. Your documents are analyzed in real-time and are not retained by Anthropic or used for model training. Anthropic maintains strict enterprise data handling policies.

Zero Data Retention Enterprise API
🗄️

PostgreSQL Database

Compliance data is stored in a dedicated PostgreSQL database with automated backups. Data is logically isolated per organization with row-level security enforced at the application layer. Your data is never commingled with other customers.

Automated Backups Row-Level Security
📁

Persistent File Storage

Uploaded permit documents are stored on enterprise-grade persistent cloud storage. Files are backed up automatically and are accessible only to authorized users within your organization.

Persistent Volumes Access Controlled

Our Security Practices

What we do every day to keep your data safe

Password Security

All passwords hashed with bcrypt before storage. Plain text passwords are never stored or recoverable.

Secure Sessions

JWT tokens expire automatically. Sessions invalidated on logout. No sensitive data in persistent cookies.

HTTPS Everywhere

All traffic encrypted via TLS 1.3. HTTP automatically redirected to HTTPS. SSL certificates auto-renewed.

Data Isolation

Every query filtered by organization ID. Your data is never accessible to other organizations.

Automated Backups

Database and file backups run automatically. Your compliance data is protected against accidental loss.

Access Logging

All user actions and data access are logged with timestamps. Full audit trail available for enterprise customers.

Security Incident Response

Our clear process if something goes wrong

1

Detection

Immediate identification and isolation of any security issue

2

Assessment

Determine scope and impact on customer data

3

Notification

Affected customers notified promptly with full details

4

Remediation

Root cause fixed, controls improved, review completed

To report a security concern: security@aircomply.com

Security FAQ

Common questions from enterprise customers

Where is my data stored?

Your data is stored on SOC 2 Type II certified US-based cloud infrastructure provided by Railway. We do not store data outside the United States. Your permit data is never used to train AI models.

Is my permit data used to train AI?

No. We use Anthropic's enterprise API with zero data retention. Your documents are never used to train AI models by Anthropic or AirComply.

What certifications do you have?

AirComply runs on SOC 2 Type II certified cloud infrastructure provided by Railway. We are working toward our own independent certifications as we grow.

Can other customers see my data?

No. Your data is completely isolated. Every query is filtered by your organization ID. Cross-tenant access is architecturally impossible.

Do you offer an MSA or NDA?

Yes. Master Service Agreements and Non-Disclosure Agreements are available for enterprise customers. Contact us to request.

How are passwords protected?

Passwords are hashed using bcrypt before storage. We never store plaintext passwords and cannot recover them if lost.

Questions About Security?

Our team is happy to answer any security questions from your IT or legal team.

Contact Us