SECURITY OVERVIEW

Last updated July 12, 2026

This page describes how Cubic Insights LLC ("we," "us," or "our") secures ProvenFlight, available at https://www.provenflight.com (the "Services"). It is written to be specific about what we actually do. If anything here is unclear, or you need more detail for a security review, email us at admin@provenflight.com and you will get a direct answer.

OUR APPROACH

ProvenFlight is used by military aviators, aviation organizations, and others who maintain flight and flight records. Those records may include operational, personnel, and mission-related information that warrants strong protection. We treat that as the baseline threat model for every design decision, not an edge case. Our security program is designed around industry-standard practices for SaaS applications handling sensitive operational data. We do not currently hold a third-party certification or attestation; independent attestation is on our roadmap, and we would rather tell you that plainly than imply otherwise.

The product is built to help you organize aviation records efficiently, including through automated parsing of uploaded documents. You remain responsible for what you upload, how you label records, and whether parsed output is verified before use in official logbooks or reporting.

DATA PROTECTION

  • Encryption in transit. All connections to the Services are encrypted with TLS (HTTPS).
  • Encryption at rest. Customer Data is stored encrypted at rest in our database and file storage infrastructure.
  • US hosting on AWS. The Services run on Amazon Web Services in United States regions. The database runs in a private network segment that is not reachable from the internet, and uploaded files are stored in private buckets served only through authenticated application routes.
  • Organization separation. Data is logically separated by organization, and access is scoped to the requesting user's organization: users in one organization cannot access another organization's data.
  • Role-based access. Within an organization, access is governed by roles, so administrators control who on their team can see and do what.
  • Payment data. Payments are processed by Stripe using Stripe-hosted checkout and billing pages. Card numbers never touch our servers.

APPLICATION SECURITY

  • Authentication. Sign-in is via email and password or single sign-on with Google or Microsoft. Passwords are stored hashed, never in plain text. Session cookies are httpOnly and secure.
  • Two-factor authentication. Two-factor authentication is available to all users, supporting authenticator apps (TOTP) and email one-time codes, with backup codes for recovery.
  • Audit logging. The Services maintain audit logs of significant events across account, organization, and record operations, including changes to flight and flight log entries and login activity.
  • Least-privilege internal access. Internal access to production systems and data is restricted to what is needed to operate and support the Services.
  • Development practices. Every change passes automated linting, type checks, and unit and end-to-end tests before deployment, and we keep third-party dependencies up to date.

AVAILABILITY AND BACKUPS

Our database performs automated daily backups with 7-day point-in-time recovery, and we maintain and periodically test recovery procedures so that we can restore service and data if something goes wrong. We monitor the Services for errors and availability issues. Live operational status and recent uptime for the app, API, parse jobs, and marketing site are published at https://provenflight.instatus.com. We do not offer contractual recovery-time guarantees on this page; if your organization needs contractual availability commitments, contact us at admin@provenflight.com.

Pro plans can export formatted flight and flight log data from within the application. If you need a copy of your records after a plan ends, email us at admin@provenflight.com.

INCIDENT RESPONSE

We monitor the Services with error tracking and internal alerting so problems surface quickly. If we confirm a security incident affecting your data, we will notify affected customers without undue delay, consistent with applicable law. Notifications will describe what happened, what data was involved, and what we are doing about it.

RESPONSIBLE DISCLOSURE

If you believe you have found a security vulnerability in the Services, please report it to admin@provenflight.com with enough detail for us to reproduce the issue. We will acknowledge your report, investigate, and remediate confirmed issues promptly. We welcome good-faith security research, and we will not pursue legal action over research that meets all of the following conditions: the research is conducted solely to identify a vulnerability and report it to us; it does not access, modify, or destroy other users' data and does not degrade the Services; you give us a reasonable opportunity to remediate before any public disclosure; and you do not retain, use, or disclose any data or non-public information obtained in the course of the research.

This safe harbor applies only to good-faith security research as described above. It does not authorize competitive analysis, reverse engineering for any purpose other than identifying a vulnerability to report to us, or any use of the Services, their content, or research findings for competitive purposes, and it does not waive any of our rights under our Terms of Service or Responsible Use Policy. We do not currently operate a paid bug bounty program.

QUESTIONS

Security questionnaires, procurement reviews, and any other questions about this page can be sent to admin@provenflight.com.