§ TRUST · AVIATION-GRADE

Audit-grade by construction.

Six certifications, one Merkle hash-chain, zero third-party trackers on principal-facing surfaces. Discretion costs us OTA reach. We accept the trade.

OPERATOR VERIFICATION

Tail-on-certificate AOC validation, in real time.

AOC

Active operating certificates pulled from FAA/EASA/CAA registries every 6 hours.

TAIL

Each tail is matched against its operator's certificate at quote-issuance time.

AUDIT

Every verification event is appended to a Merkle hash-chain with public root commitment.

COMPLIANCE POSTURE

Six certifications, ranked by audit cadence.

SOC 2 II

Type II audit · target attestation Q3 2026.

ISO 27001

Information security management · target Q4 2026.

PCI-DSS 4.0

Service-provider scope · in continuous attestation.

GDPR

Principal data residency in EU/UK/CH at member's election.

FAA 135

Operator integration audit posture.

NBAA IS-BAO 2

Operator partners audited at Stage 2 minimum.

DATA RESIDENCY & ENCRYPTION

GCP CMEK · VPC-SC perimeter · Spanner audit log.

CMEK

Customer-managed encryption keys per tenant · Cloud KMS HSM-backed.

VPC-SC

Service perimeter prevents data exfiltration to outside-perimeter services.

MERKLE

Spanner audit log entries hash-chained · root commits to BigQuery hourly.

PAYMENTS

Paynode-class cross-border. Apple Pay, wire, escrow.

ESCROW

Funds held in named-trust account · per-leg release at wheels-up. jet card · escrow →

FX

Multi-currency settlement at mid-market rate · monthly statement.

KYC/AML

Tier-3 verification on principal accounts · enhanced for invitation-tier.

PRIVACY

Discretion architecture, not a checkbox.

NO PIXELS

Zero third-party trackers on principal-facing surfaces. Inspect at your leisure.

NO SALE

Principal data is never sold, ever. Operator data is contractually protected.

NO ADTECH

We don't run ads. We don't buy ads. We don't measure for ad networks.

§ AUDIT

Hash-chained, offline-verifiable.

Every quote, modification, and confirmation is appended to a Merkle hash-chain on Spanner. Operators export a CSV/JSON snapshot; auditors verify the root offline. We publish the root weekly.

SECURITY.TXT
Contact: mailto:security@oneways.ai
Expires: 2027-12-31T23:59:59.000Z
Encryption: https://oneways.ai/.well-known/pgp.asc
Preferred-Languages: en
Canonical: https://oneways.ai/.well-known/security.txt
Policy: https://oneways.ai/trust#disclosure
Hiring: not publicly
STATUS

Real-time platform health, region by region, service by service.

status.oneways.ai →
DISCLOSE A VULNERABILITY

Coordinated disclosure within 90 days. Recognition page on request, anonymity respected.

security@oneways.ai →