System-of-record disclaimer

The airport remains responsible for its official procurement file and FAA, state, and local record-retention obligations.TarmacSync exports are advisory drafts as of the timestamp shown.

Security at a glance

Encryption and tenant separation

TLS 1.2+ protects connections, and Neon Postgres provides AES-256 encryption at rest. Application queries are scoped to the authenticated organization so airport workspaces remain separated.

Authentication and MFA

Passwordless email one-time-code sign-in. Two-factor authentication via authenticator app (QR code setup, TOTP RFC 6238) or email one-time code. 10 recovery codes per user. Administrators can require 2FA organization-wide.

Airport data handling

Procurement and project data is stored in U.S. infrastructure by default. Procurement sessions, evidence packets, and audit events are retained for seven years; AI conversation data may be retained for a shorter period. Generated drafts are not the airport's official system of record.

Data export and deletion

Authorized workspace owners can export organization-scoped data from Settings. Account and organization deletion requests are handled through support, subject to applicable retention requirements and written agreements.

Incident-response practices

TarmacSync maintains an incident-response procedure for triage, containment, recovery, and notification. Security reports are acknowledged within two business days; affected organizations are notified within 72 hours of confirming a breach.

Accessibility

WCAG 2.2 Level AA is the documented standard, with automated axe-core checks across primary workspace routes. A VPAT draft and the current known-limitations summary are available on request.

DPA and subprocessor information

The Data Processing Addendum lists active subprocessors, data-handling practices, and cross-border transfer commitments. Available provider DPAs can also be included in an airport's review package. Questions: security@tarmacsync.com.

Additional technical controls

Audit logging

Critical actions write a domain record and transactional outbox before delivery. Audit coverage includes procurement activity, organization administration, and authorization events.

Rate limiting

Sliding-window controls are enforced across instances through Upstash Redis. Cost-bearing and authentication buckets fail closed if the limiter is unavailable.

Security headers

Hosted deployments use X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, HSTS, and a nonce-based Content-Security-Policy.

Infrastructure and secrets

The hosted service uses a U.S. region by default. Application secrets are stored as server-side environment variables and are not exposed to the browser.

Database enforcement rollout

Row-level-security policies are staged as an additional tenant boundary and require production rollout validation.

Accessibility limitations

Screen-reader testing, the VoiceOver and Safari checklist, focus confinement in four secondary dialogs, and third-party VPAT review remain incomplete.

The airport remains responsible for determining its own security, privacy, records, and procurement requirements before using the service.

Compliance scope

FedRAMP

Not authorized. TarmacSync is not designed for CUI or FISMA-covered systems. It is a procurement planning aid — not a system of record.

SOC 2 Type II

Application hosting (Vercel) and the database (Neon), where all airport data is stored and processed, are SOC 2 Type II. TarmacSync has not yet completed its own organizational SOC 2 audit — planned when enterprise requirements materialize. Infrastructure SOC 2 reports from Vercel and Neon are available on request.

Penetration test

Planned. Scheduled before enterprise tier launch.

SaaS tier

Suitable for non-federal procurement planning data with a signed DPA.

Reporting a security issue

Report vulnerabilities or security concerns to security@tarmacsync.com. We aim to acknowledge reports within two business days.

Request documentation

Airport teams and RFP evaluators can request:

Email security@tarmacsync.com or contact@tarmacsync.com.