Encryption and tenant separation
TLS 1.2+ protects connections, and Neon Postgres provides AES-256 encryption at rest. Application queries are scoped to the authenticated organization so airport workspaces remain separated.
TarmacSync is procurement intelligence for U.S. airport operators — a planning aid, not a grant ERP, bid portal, or official system of record. This page summarizes our security posture, accessibility standard, and compliance scope for evaluation by airport teams.
System-of-record disclaimer
The airport remains responsible for its official procurement file and FAA, state, and local record-retention obligations.TarmacSync exports are advisory drafts as of the timestamp shown.
TLS 1.2+ protects connections, and Neon Postgres provides AES-256 encryption at rest. Application queries are scoped to the authenticated organization so airport workspaces remain separated.
Passwordless email one-time-code sign-in. Two-factor authentication via authenticator app (QR code setup, TOTP RFC 6238) or email one-time code. 10 recovery codes per user. Administrators can require 2FA organization-wide.
Procurement and project data is stored in U.S. infrastructure by default. Procurement sessions, evidence packets, and audit events are retained for seven years; AI conversation data may be retained for a shorter period. Generated drafts are not the airport's official system of record.
Authorized workspace owners can export organization-scoped data from Settings. Account and organization deletion requests are handled through support, subject to applicable retention requirements and written agreements.
TarmacSync maintains an incident-response procedure for triage, containment, recovery, and notification. Security reports are acknowledged within two business days; affected organizations are notified within 72 hours of confirming a breach.
WCAG 2.2 Level AA is the documented standard, with automated axe-core checks across primary workspace routes. A VPAT draft and the current known-limitations summary are available on request.
The Data Processing Addendum lists active subprocessors, data-handling practices, and cross-border transfer commitments. Available provider DPAs can also be included in an airport's review package. Questions: security@tarmacsync.com.
Critical actions write a domain record and transactional outbox before delivery. Audit coverage includes procurement activity, organization administration, and authorization events.
Sliding-window controls are enforced across instances through Upstash Redis. Cost-bearing and authentication buckets fail closed if the limiter is unavailable.
Hosted deployments use X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, HSTS, and a nonce-based Content-Security-Policy.
The hosted service uses a U.S. region by default. Application secrets are stored as server-side environment variables and are not exposed to the browser.
Row-level-security policies are staged as an additional tenant boundary and require production rollout validation.
Screen-reader testing, the VoiceOver and Safari checklist, focus confinement in four secondary dialogs, and third-party VPAT review remain incomplete.
The airport remains responsible for determining its own security, privacy, records, and procurement requirements before using the service.
Not authorized. TarmacSync is not designed for CUI or FISMA-covered systems. It is a procurement planning aid — not a system of record.
Application hosting (Vercel) and the database (Neon), where all airport data is stored and processed, are SOC 2 Type II. TarmacSync has not yet completed its own organizational SOC 2 audit — planned when enterprise requirements materialize. Infrastructure SOC 2 reports from Vercel and Neon are available on request.
Planned. Scheduled before enterprise tier launch.
Suitable for non-federal procurement planning data with a signed DPA.
Report vulnerabilities or security concerns to security@tarmacsync.com. We aim to acknowledge reports within two business days.
Airport teams and RFP evaluators can request: