Protecting pilot training data and platform integrity — a comprehensive overview of the security measures that keep your JetGuide experience safe, private, and trustworthy.
Every byte of your training data — in transit and at rest — is protected by industry-leading encryption standards.
All data transmitted between your browser and JetGuide servers is encrypted in transit using the latest TLS protocols.
Account profiles, training records, AI interaction logs, and SMS history are all encrypted at rest using AES-256.
Database backups are encrypted and stored in geographically redundant locations for resilience and disaster recovery.
Passwords are never stored in plain text. We use bcrypt hashing with unique per-user salts for maximum credential security.
JetGuide's platform is built on enterprise-grade cloud infrastructure with rigorous isolation, monitoring, and patch management practices.
Our infrastructure is hosted on enterprise-grade cloud services holding SOC 2 Type II certification — the gold standard for security, availability, and confidentiality controls.
Production environments are fully isolated from development and staging environments, preventing cross-contamination of live data.
Network access is restricted by firewall rules and security groups. No direct database access is exposed to the public internet.
Regular automated vulnerability scans and dependency audits run continuously. Critical security patches are applied within 72 hours — ensuring rapid response to emerging threats.
Access to JetGuide systems is governed by layered controls — from multi-factor authentication to role-based permissions and enterprise SSO.
MFA is available for all user accounts and is required for all administrator accounts — adding a critical second layer of protection beyond your password.
Session tokens expire after inactivity and are immediately invalidated on logout, preventing unauthorized session reuse.
RBAC limits employee and contractor access to only the data required for their specific function — enforcing least-privilege principles.
All administrative access to production systems is logged and monitored, creating a complete audit trail for accountability.
Enterprise and Part 141/142 customers can enable Single Sign-On via SAML 2.0, integrating JetGuide with your existing identity provider.
JetGuide is built following industry best practices to defend against the most common and critical web application vulnerabilities.
Built following OWASP Top 10 guidelines to systematically mitigate the most critical web application security risks.
Applied throughout the platform to prevent injection attacks and data manipulation.
CSP headers are enforced across the platform to mitigate cross-site scripting (XSS) risks and unauthorized script execution.
Applied to authentication endpoints to prevent brute-force attacks and credential stuffing attempts.
Third-party dependencies are regularly reviewed and updated to eliminate known vulnerabilities in the software supply chain.
Your training interactions power a personalized learning experience — and we are committed to using that data responsibly, transparently, and only for your benefit.

Training responses, quiz results, and AI coaching interactions are used solely to personalize your experience and improve platform performance.
Training data is not shared with third-party AI providers for model training purposes without your explicit consent.
Our AI systems do not have access to flight operational data, FOQA data, or any safety-sensitive airline systems.
De-identified, aggregated training analytics may be used to improve learning outcome models — never tied to individual identities.
JetGuide's daily SMS oral exam questions are delivered through a secure, compliant messaging infrastructure — with your privacy and control always front of mind.
Daily SMS questions and AI replies are transmitted via Twilio's A2P 10DLC compliant messaging infrastructure, meeting all carrier registration requirements.
All SMS message content is encrypted in transit per carrier and platform standards, protecting your messages from interception.
SMS interaction history is stored with the same AES-256 encryption standards applied to all other training data on the platform.
Users may opt out of SMS messages at any time by replying STOP to any JetGuide message. We will never send unsolicited SMS or share your phone number for marketing.
In the event of a security incident affecting user data, JetGuide follows a structured, time-bound response process to protect users and restore trust.
JetGuide is committed to transparency. Affected users will be notified within 72 hours of a confirmed incident, as required by applicable regulations.
JetGuide's security and data practices are designed to meet rigorous regulatory and industry standards across payment processing, privacy, and messaging.
Payment data is processed through a PCI-DSS compliant payment processor. JetGuide does not store raw card data.
Our data practices are designed to comply with the California Consumer Privacy Act (CCPA) and applicable data protection regulations.
SMS messaging infrastructure complies with CTIA guidelines and A2P 10DLC carrier registration requirements.
Enterprise customers requiring a Data Processing Agreement (DPA) or Business Associate Agreement (BAA) may contact legal@jetguide.com.
Security is a shared responsibility. Here's what you can do to keep your JetGuide account and training data secure.
Use a strong, unique password — never reuse passwords from other services.
Enable multi-factor authentication for an extra layer of protection.
Never share your credentials with other pilots, instructors, or administrators.
Report suspicious emails to security@jetguide.com. We will never ask for your password via email or SMS.
Log out on shared devices after every session.
JetGuide, Inc.
Attn: Security Team
3007 East Harwell Road
Phoenix, AZ 85042
Security: security@jetguide.com
Legal (DPA/BAA): legal@jetguide.com
JetGuide Security