Security
Last updated June 2026
We take security seriously because we expect you to trust us with your work.
Trust is earned through good engineering, not good marketing.
How we build
We keep our systems simple, limit unnecessary complexity and avoid collecting data we do not need.
Simple systems are easier to understand.
Systems people can understand are easier to secure.
Your connection
All communication between your device and our servers is encrypted.
Data stored on our systems is encrypted at rest using modern industry standards.
Who can access your data
Access is limited to the people who need it to support customers, maintain the service or respond to security incidents.
Access is logged and reviewed.
Your account
We encourage two-factor authentication wherever available.
Passwords are never stored in plain text. We can reset them. We cannot read them.
If something goes wrong
No software is perfectly secure.
If we discover a security incident affecting customer data, we'll investigate it immediately, contain it and notify affected users as quickly as reasonably possible.
We'll explain what happened, what was affected and what we're doing about it.
Found a vulnerability?
We'd much rather hear from you than read about it online.
If you discover a security issue, email security@svair.org.
Please give us a reasonable opportunity to investigate and fix the issue before disclosing it publicly.
If you act in good faith, we'll do the same.
One last thing
Security is never finished.
It's a process of constantly finding weak spots and making them stronger.
That's the standard we hold ourselves to.