Skip to content
FlightReady
  • Product
  • Case Study
  • Pricing
  • Company

    • AboutCompany overview
    • BlogLatest Insights
    • CareerJoin our team
    • ContactGet in touch

    Useful

    • ChangelogLatest updates
    • WaitlistJoin early
    • Terms & ConditionsLegal terms of use
    • Privacy PolicyHow we handle data
    Whats Newlearn more
log in / sign upget started

Security

How We Handle Your Data

Last reviewed: September 1, 2026

What This Page Is

This page describes how FlightReady handles your data, stated only as far as we can back it up. It is written to be checkable rather than reassuring. Where we have nothing to show you, the page says so instead of reaching for a badge.

Signing In

Accounts and sessions are handled by Supabase Auth. Your browser never talks to the database directly. It holds a signed session token, and the API verifies that token on the server before it will answer for your account. Access is constrained a second time inside the database itself: row-level security policies scope your rows to you, so a valid token belonging to somebody else does not read your assessments.

Passwords are handled by Supabase and are never stored by us in any form. If you delete your account, the sign-in identity goes with it.

Encryption in Transit

The site, the API and every outbound call to a weather, airport, traffic or accident data provider run over HTTPS. There is no plaintext hop anywhere in the path a briefing takes from a public data service to your screen, and no provider we query is reached over an unencrypted endpoint.

Where Your Data Lives

Your account, the aircraft you save, the personal minimums you set and the assessments you keep live in a managed Postgres database provided by Supabase, hosted on infrastructure that encrypts its storage volumes. We rely on that provider for disk-level encryption and for the physical security of the hardware. We do not run our own servers, and we do not claim our own certification for somebody else's data centre.

Your Flights Are Not Training Data

We do not use your routes, your assessments or your briefings to train models, and we do not assemble them into training sets. Briefing text is generated per request from the data retrieved for that request. Model inference runs through third-party providers under their published terms; we do not enrol your data in any training programme with them. This is the same commitment made in the Privacy Policy, and it is the one to hold us to: read the Privacy Policy

Secrets and Configuration

Credentials that can act on your behalf — the database connection, the Supabase service role key, the billing and model provider keys — are server-side only and never reach a browser bundle. In production the API refuses to start at all if a required secret is missing, rather than starting in a quietly degraded state, and it refuses to start with development bypass flags enabled. A billing webhook that arrives without a verifiable signature is rejected rather than accepted.

How Long Source Data Is Kept

Public source data is cached briefly, so that repeating an analysis does not hammer a public service and so that what you are shown is current. Surface observations and forecasts are held for about ten minutes, SIGMETs for five, G-AIRMETs for ten, NOTAMs for thirty, live ADS-B traffic for well under a minute, and airport and airspace records for hours rather than minutes. The NTSB accident dataset is a published bulk file, ingested and held locally as reference data. None of that is personal to you, and none of it identifies you.

What is personal to you — your account, your aircraft, your minimums and the assessments you chose to save — is kept under your account until you delete it. You can delete an individual assessment, or the account and everything under it, at any time.

What We Do Not Claim

FlightReady is not SOC 2 certified. It is not ISO 27001 certified. It has not been HIPAA or PCI assessed, and we have not commissioned or published a third-party penetration test. We hold no FAA approval of any kind, and no part of this service is a certified dispatch system or an official weather briefing. If any of that changes, this page will say so, with a date on it.

Card details are handled by Stripe and never touch our servers, which is why we do not need to make a PCI claim of our own.

Reporting Something

If you believe you have found a vulnerability or a data-handling problem, write to us with enough detail to reproduce it and we will come back to you. We would much rather hear about it early and awkwardly than late: support@flightready.ai

Advisory Use Only

None of the above changes what the service is. FlightReady provides advisory preflight risk intelligence only. It is not an official weather briefing, a certified dispatch system, or a replacement for pilot-in-command judgment. Where a data source is unavailable the service marks that factor unknown, and an unknown factor must never be read as a low-risk one. The pilot in command makes all final operational decisions: read the terms

1]?:dM2;<_uL0{!njJ3[>|eIx}&bpZ1]?:dMz+%ctY0{!njJ$/^waSx}&bpZ;<_uL8z+%ctY[>|eI9$/^waS]?:dM2;<_uL8

Ready to Brief Your Next Flight?

Join the pilots and flight schools using FlightReady to make preflight risk something they can see, explain, and talk through before departure.

see pricingTalk to sales

FlightReady

Advisory preflight risk intelligence for general aviation pilots, instructors, and flight schools.

© 2026 FlightReady, LLC · Advisory use only. Read the terms

Main

  • Product
  • About
  • Pricing
  • Case Study
  • Blog
  • Contact

Useful

  • Use Cases
  • Industry
  • Teams
  • Career
  • Changelog
  • FAQ

Others

  • Security
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy
  • Waitlist
  • Sitemap

Elsewhere

  • LinkedIn
  • Instagram
  • Email us
  • Sign in
FlightReadyFlightReady