+Security & trust

Your operation's records, secured and inspection-ready.

Schedules, balances, member details, signed maintenance records and years of aircraft history live in Resyrv. Every organization's data is isolated at the database, every signature is PIN-verified and tamper-evident, and card numbers never reach our servers.

How Resyrv protects your data

Security at every layer of Resyrv.

01

Customer data protection

  • Every organization is isolated by the database itself: row-level security policies bound to your organization mean the database will not return another organization's rows, even if the application has a bug.
  • All traffic is encrypted in transit with TLS, and HTTP Strict Transport Security keeps browsers from ever connecting unencrypted.
  • Data at rest is encrypted by the managed database and object storage providers.
  • Signed records are never edited in place. A signed logbook entry, work order or training record can only be amended by a new record or voided with a reason; the original stays.
02

Infrastructure

  • Hosted on DigitalOcean in the United States, behind Cloudflare's global network.
  • The database is a managed PostgreSQL cluster with daily automated backups and point-in-time recovery.
  • Uploaded documents are stored in private object storage and served through short-lived signed links, never from a public bucket.
03

Application

  • Cloudflare screens requests at the edge and absorbs denial-of-service traffic before it reaches the application.
  • Every response carries a strict Content Security Policy and a full set of security headers (frame protection, MIME-type pinning, referrer and permissions policies).
  • Card details are entered in fields hosted by Stripe or Authorize.net, so card numbers never reach Resyrv.
  • Uploaded files are served as downloads, not rendered in the browser.
04

Compliance and privacy

  • Electronic signatures and recordkeeping follow AC 120-78A and FAR 43.12: a PIN unique to the signer, the certification wording stored with the record, and a fingerprint of what was signed.
  • Personal information is handled under PIPEDA for Canadian organizations and the CCPA for California residents, with self-service export and deletion.
  • Global Privacy Control signals are honored automatically; analytics and advertising cookies stay off until a visitor opts in.
  • A named privacy officer is accountable for personal information, and the privacy policy explains how a breach would be handled.
05

Organization security

  • Uptime and API health are monitored around the clock, with incident status published at status.resyrv.com.
  • Updates roll out without downtime, so your records stay available during a release.
  • Every release must pass the full automated test suite before it reaches production.
  • Security reports sent to [email protected] go straight to engineering and get a prompt reply.
06

Account protection

  • Sign-in is handled by Clerk, a dedicated identity provider, with Google, Apple and email sign-in and session revocation.
  • Inside an organization, every action is permission-gated from a baseline member grant upward; a member cannot act beyond what their role allows.
  • Signature PINs are stored as bcrypt hashes separate from the login password, and five wrong attempts lock signing for fifteen minutes.
  • Signing, return to service, refunds and payment adjustments write to an audit log that records who did what, when, and to which record.

Security at a glance

The short answers for your vendor review.

Send your security or privacy questionnaire to [email protected] and we will complete it. Use the same address to report a vulnerability.

Tenant isolation
Database row-level security
Encryption in transit
TLS everywhere, HSTS enforced
Encryption at rest
Managed database and object storage
Edge protection
Cloudflare network, strict CSP and security headers
Authentication
Clerk (dedicated identity provider)
Electronic signatures
PIN-verified, statement stored, SHA-256 fingerprint
Payment processing
Stripe (PCI DSS Level 1) or Authorize.net, hosted card entry
Card storage
None; brand and last four only
Backups
Daily automated, point-in-time recovery
Data rights
Self-service export and account deletion
Privacy officer
Jonathon Carr, [email protected]
Status page
status.resyrv.com
Security contact
[email protected]

Questions about security or compliance? We will walk through any of these details with you directly.

Get started

See it with your own aircraft.

Add your aircraft and your rates, then see the schedule, the squawks, and the ledger all work off one record. No card required.