Isolation, auditability and portability — by construction.
FlyerOS is multi-tenant from the first table. Security posture is designed into the data model and authorization layer, not bolted on afterwards.
Tenant isolation
Every tenant-owned table carries an organisation key with row-level security. Automated tests assert that a member of one organisation cannot read or write another’s records — through the UI, API, crafted IDs, file URLs or exports.
Capability-based authorization
Access is evaluated server-side from an authenticated membership: identity → membership → scope → permission → entitlement → record → state. Client-supplied role or organisation IDs are never trusted.
No self-elevation
Role and permission changes require high privilege, are server-only, and are written to an immutable before/after audit. A user cannot escalate their own role by editing a request payload.
Server-side secrets
Provider credentials, webhook secrets and privileged database clients live only in server/worker contexts. The browser never receives a service key.
Immutable audit & evidence
Privileged and security actions append to an immutable audit trail. Training, safety and compliance records use versioned amendments rather than silent overwrites.
Files, scoped and signed
Objects are namespaced by organisation, served through short-lived signed URLs, and access is checked — never derived from mere knowledge of an object key.
Confidential safety data
The safety module supports confidentiality by design: reporter identity is separable and restricted cases use case-level access on top of ordinary permissions.
Portability & resilience
Schools can export their own operational records and documents. Integrations are first-class, not a hostage mechanism.
GDPR-oriented model
The school is the controller and FlyerOS the processor for hosted data, with retention classes, legal-hold exceptions and data-subject request workflows.
For enterprise & institutional buyers
The questions a procurement or data-protection assessment asks — answered plainly, including where something is planned rather than in place today.
Data residency
Data is hosted in the UK/EU region. Region choice for groups with specific residency requirements is available on enterprise agreements — talk to us about your requirement.
Sub-processors
We use a small, named set of infrastructure sub-processors (cloud hosting, database and email delivery). The current list is provided with the DPA, and we notify customers before it changes.
Backup & recovery
PlannedThe database is continuously backed up with point-in-time recovery by our infrastructure provider. Restore procedures are documented; scheduled restore-testing is on our roadmap.
Retention & deletion
Records are retained while your account is active and thereafter as you direct, reconciled with the regulatory retention a training organisation must observe. Deletion and export requests are honoured under the DPA.
Incident response
We monitor the service, and on a security or availability incident we notify affected customers with what we know and what we are doing, and follow up with a summary. Formal notification timeframes are set out in the DPA.
Our access to your data
FlyerOS staff can access customer data to support and operate the service. Every such access is logged and surfaced in your own audit trail — access is unrestricted for support but never unlogged.
Certifications
PlannedFlyerOS is built to recognised security practices (tenant isolation, least privilege, encryption in transit and at rest). We do not hold a formal certification such as ISO 27001 or SOC 2 today; pursuing one is on our roadmap and we will not claim it before it is held.
Penetration testing
PlannedWe run internal security review and automated checks. An independent third-party penetration test is planned ahead of general availability, and a summary will be available to customers under NDA.
Our data processing agreement is available on request — see the DPA page. Availability and service credits are on the SLA page.
FlyerOS is designed to help schools operate their approved or declared procedures. It does not itself confer regulatory compliance, certification or approval.