Back to Aero Axios

Security

Crew records are personnel data with medical and identity documents attached. Here is how the platform is built to hold them.

Last updated 8 September 2026 · Eraaz Tech

Tenant isolation is structural

Every operator’s records live in their own database schema, and a request is bound to exactly one of them for its whole lifetime. There is no shared table with an operator column, so there is no query that could return another operator’s rows by omitting a filter — the usual way multi-tenant systems leak.

After sign-in, the operator identity comes only from the signed session token. It cannot be changed by a header, a query parameter or anything else a client controls.

Sessions and tokens

  • Tokens are held in HttpOnly cookies — browser JavaScript cannot read them, so a script injection cannot steal a session.
  • The browser never receives a raw API token; every authenticated call is signed server-side.
  • Access tokens are short-lived and renewed automatically; the renewal token is rotated on every use.
  • A reused renewal token is treated as theft: the session is refused and the user must sign in again.
  • Only one active session exists per account at a time.
  • Closing the browser — or the tab — ends the session.

Passwords

Passwords are hashed with Argon2id, a memory-hard algorithm chosen to make offline cracking expensive. We never store, log or transmit a password in a recoverable form, and nobody at Eraaz Tech can read yours. Invite and password-reset links are single-use, expire, and are themselves stored only as hashes.

Sign-in, password-reset and admin login are rate limited. Authentication failures return a deliberately generic message so the system never reveals whether an address exists.

Documents and photographs

Certificate scans and crew photographs are stored in private object storage. There is no public URL for any file: the bytes are streamed through an authorised request, and the storage location is never exposed to a client. Uploads are checked by inspecting the file’s actual contents rather than trusting its name or declared type.

Access control

Permissions are enforced on the server for every request — the interface hiding a button is a convenience, never the control. Roles separate configuration from roster building, and a planner can be scoped to a single base so they only see the crew and duties at that base.

Reporting a vulnerability

If you believe you have found a security issue, please email contact@aeroaxios.com with enough detail to reproduce it. Please do not test against a live operator’s data or run automated scans without written permission. We will acknowledge your report and keep you updated while we fix it, and we will credit you if you would like.

Questions about this document?

Write to contact@aeroaxios.com or post to Eraaz Tech, Radhe Radhe, Madhyapur Thimi-5, Bhaktapur, Nepal.