This policy is provided for review and must be confirmed by legal counsel before public launch.
This Security Policy describes the measures Airfree takes to protect the platform, its customers, and the data entrusted to us. Security is engineered into the platform rather than added afterwards.
1. Governance
Airfree maintains an information-security programme aligned to recognised standards, with defined ownership, risk management, and regular review. Security responsibilities are assigned at group level with reporting into senior management.
2. Identity and access
Access to the Services is authenticated through a centralised single sign-on identity provider using modern OAuth/OIDC flows with PKCE. Access to production systems follows least-privilege and need-to-know principles, and administrative access is restricted, logged, and protected by strong authentication.
3. Data protection
Data is encrypted in transit using current TLS. The platform enforces tenant isolation and least-privilege database access, so services and tenants cannot read or modify data outside their scope. Secrets are managed securely and never exposed in logs or client code.
4. Platform and network security
The platform is defended in depth: a hardened edge with an authenticating gateway in front of internal services, network segmentation, host and container hardening, and continuous vulnerability scanning of images and dependencies. Management interfaces are restricted to trusted networks and administrative VPN access.
5. Monitoring and incident response
We operate centralised logging, monitoring, and error tracking to detect anomalies and security events. We maintain an incident-response process covering detection, containment, eradication, recovery, and post-incident review, and will notify affected customers and regulators of eligible data breaches as required by law.
6. Resilience and backups
We take regular backups and maintain recovery procedures designed to restore the Services and data after a disruption. Backup integrity is verified, and off-site copies are maintained to support disaster recovery.
7. Reporting a concern
Suspected vulnerabilities should be reported under our Vulnerability Disclosure policy. Other security concerns can be raised via /contact.