Security at AirOne

Your business data is your most valuable asset. We've built AirOne with security as a foundational principle — not an afterthought.

Standards & frameworks we align to

Certifications are in progress — we show a badge only once a certificate or report is actually issued. See our compliance posture for current status.

ISO 27001

ISMS controls mapped — certification in progress

SOC 2 Type II

Controls aligned — audit not yet completed

GDPR Ready

Designed for European data-protection readiness

IT Act 2000

Aligned to Indian IT Act 2000 requirements

How we protect your data

Enterprise-grade security practices built into every layer of the platform.

Encryption at Rest & In Transit

All data is encrypted with AES-256 at rest. All communication is over TLS 1.3. Encryption keys are rotated regularly and stored in an isolated key management service.

Access Controls & Audit Logs

Identity & access management (IAM) with roles, policies, and fine-grained permissions. Every action is logged with user, timestamp, and IP — giving you a complete audit trail.

Infrastructure Security

Compute runs on AWS EC2 in private subnets in ap-south-1 (Mumbai), with the public API edge load-balanced by HAProxy and the application and worker tiers kept private. The frontend is served from Cloudflare Pages and user files from Cloudflare R2. Our infrastructure undergoes regular third-party penetration testing.

Resilience, Backups & Disaster Recovery

Data runs on a self-managed YugabyteDB distributed-SQL cluster with synchronous, quorum-based replication across nodes: committed transactions survive a node failure with no data loss (RPO = 0), and on a node or leader failure the cluster fails over automatically in seconds (RTO in seconds) with no manual restore. For a region-wide outage or a logical/data-corruption error, recovery is instead via automated daily backups (30-day retention) and point-in-time recovery — a restore with a longer recovery time.

Vulnerability Management

Continuous dependency scanning, SAST/DAST pipelines, and a responsible disclosure program. Critical vulnerabilities are patched within 24 hours.

Compliance & Audits

We are working toward third-party security audits and run internal reviews, with our controls mapped to the ISO 27001 and SOC 2 frameworks.

Additional Security Practices

Multi-factor authentication (MFA) enforced for all accounts
Single Sign-On (SSO) support via SAML 2.0 and OAuth 2.0
Session management with configurable timeouts
IP allowlisting for enterprise accounts
API rate limiting at the HAProxy edge and application layer; DDoS protection via Cloudflare on the frontend
Secrets management with HashiCorp Vault
Zero-trust network architecture internally
Employee security awareness training quarterly

Privacy & data controls, built into the product

Security isn't just our infrastructure — these controls are available to you inside AirOne.

Granular IAM & permission engine with custom roles and full audit logs
End-to-end encrypted team & direct messaging
Consent management & Data Subject Requests — access, correction, erasure, portability
Versioned legal-document acceptance tracking with effective dates
Encrypted file vault plus a password & API-secret vault with access control
Tokenized, expiring public file links and single-use collaboration access keys
Automated database backups with retention, download, and restore
PCI-DSS-compliant payments — card data is tokenized and never stored on our servers
Multi-tenant data isolation enforced at the database with row-level security

Exercise your rights anytime via the data request page or our compliance posture.

Responsible Disclosure

Found a security vulnerability? We appreciate responsible disclosure. Report it to our security team and we'll acknowledge within 24 hours and keep you updated throughout the resolution.

dhinagaran.s@airavadwebsolutions.com

Please don't disclose publicly until we've had a chance to address the issue.

Have questions about our security posture? Talk to our team.

Contact Us