Skip to content
Compliance & records

The records the CAA asks for, kept as a by-product of the day

Written for a Head of Training, a CFI or an accountable manager. What FlyerOS records, produces and refuses — with every capability marked live, preview or planned, honestly.

FlyerOS helps you operate your approved or declared procedures. It does not itself confer certification or approval — every regulatory rule is modelled with its source, jurisdiction and effective date so your school stays in control.

Training records that stand up

Planned
ORA.GEN.220ORA.ATO.120

Every lesson is recorded with what was covered, the grade, and who signed it — and, crucially, who can prove they signed it. A record is signed by an identified person, and that signature is bound to the record rather than to a printout that can be swapped later.

A correction never overwrites. An amendment is appended, carrying who made it, when and why, so the original stands beside the correction and the history is intact. That is what reliable traceability and protection from alteration mean in practice, and it is retained for the period a training organisation is expected to keep records after a course completes.

Knowing who did what, inside your own school

Planned

The transparency a Head of Training actually cares about is internal: who signed that lesson, who changed a grade after the fact, who deferred that defect, who moved a booking the morning of a skill test. Every record carries its own history in place — created by whom, every amendment, who made it, when and why — append-only, so the original is never lost and a correction sits visibly beside what it corrected.

It is scoped by role: an instructor sees their assigned students, an accountable manager sees everything. In most schools this lives in a paper folder, a shared drive and somebody’s memory. Here it is a by-product of running the day, maintained by nobody.

Theoretical knowledge and examinations

Planned
Recommendation validitySRG2155

FlyerOS records the recommendation validity clock — the eighteen-month window that runs from the end of the calendar month of first attempt — along with attempts per subject, the number of sittings, and the pass mark, so a student’s theoretical-knowledge position is a fact rather than a reconstruction.

It records examination paper custody and the reporting a school owes, so the SRG2155 return is assembled from records you are already keeping. It does not sit the exam or guarantee an outcome; it keeps the record straight.

Instructor qualifications and privileges

Planned

Licences, ratings, medicals and instructor privileges are structured data with expiry dates, not a wall of certificate scans. The schedule reads them: it refuses to book an instructor for something they are not currently authorised or current to do, and it says why.

Instructor flight time limitations

Preview
ORA.ATO.130(d)Appendix 1

Duty and flight-hour limits are modelled as rolling windows and checked when a booking is made, not discovered afterwards. A booking that would breach a limit is refused with the reason, so the limitation shapes the roster rather than being reconciled after the month closes.

Aircraft airworthiness and the schedule

Planned

Maintenance due-dates, open defects and deferrals make an aircraft unbookable in the calendar — automatically, the moment they are recorded. A forecast looks forward: an aircraft that will be out of hours by the fourteenth cannot be booked for the fourteenth, because eligibility is evaluated for the time the flight is scheduled for, not the moment it was booked.

Occurrence and safety reporting

Planned

Confidential occurrence reporting, a hazard and risk register, and corrective actions tracked to closure — with the tighter access controls safety data deserves. Reports export in an ECCAIRS-ready form, so the external obligation is a query rather than a re-keying exercise.

Your inspection

Planned

At a standardisation visit or a continuation audit an inspector asks for specific evidence about specific people, aircraft and dates. FlyerOS assembles it as an evidence pack — scoped to what was asked, date-filtered, read-only and expiring — from the records the day already produced, rather than a fortnight of reconstruction.

This section is meant to be useful to your school whether or not you ever buy FlyerOS: it is a plain description of what a UK inspection actually asks for.

DTO obligations

Planned

The annual internal review and the annual activity report are assembled from records a declared training organisation is already keeping day to day — not written from memory once a year against a deadline.

Where your records live, and who can see them

The questions an accountable manager actually asks, answered plainly.

Where is our data held?
On managed infrastructure in the UK/EU region, with encryption in transit and at rest. Data-residency options are set at the organisation level.
Who at FlyerOS can see our students’ records, and is it logged?
Support and operations staff may access your data to run and support the service, and every such access is written into your own audit trail — you can see it. There is no hidden access.
Can another school ever see our data?
No. Every record is scoped to one organisation and access derives from an authenticated membership of that organisation. A member of one school cannot read another’s records.
What happens to our records if we stop using FlyerOS?
You export everything — training records, flight records, documents — in usable formats, at no cost, including after you leave. Your regulator expects you to hold those records and we do not stand between you and them.
How long are records kept?
For as long as your account is active and thereafter as you direct, reconciled with the retention a training organisation is subject to. Deletion and return follow the data processing agreement.
What happens if you have an outage, or go out of business?
There is a published service level agreement with an availability commitment and service credits, and your right to export your own data at any time means your records never depend on us being here.
Technical detail for your IT reviewer

Strict tenant isolation (row-level, on every tenant-owned table), capability-based authorization evaluated server-side from an authenticated membership, an append-only audit trail for privileged actions, server-side-only secrets, and GDPR-oriented controller/processor controls.

The full architecture write-up lives on the security overview.

The commercial terms behind this — data processing agreement, service level agreement and privacy policy — are all published.

See how your records would look in an inspection