What is in place
- HTTPS / TLS for Web, Admin, and API.
- Role-based access control (RBAC) on staff APIs and Admin UI.
- Audit logging for operational and security-relevant actions.
- Application-level encryption (AES-GCM) for selected sensitive fields such as passport and insurance policy numbers.
- Private document download for compliance PDFs (authenticated staff).
- Customer-safe APIs that omit operator buy prices and aircraft registration.