Trust

Security

Last updated · 10 August 2026

Disruption spend is real money moving fast, on real passengers. These are the rules the system enforces, not aspirations.

Human sign-off

We never determine EU261 eligibility; that decision stays with the airline. An operator approves every spend, and automation runs only inside pre-approved policy envelopes.

Policy enforced in code

Rate ceilings, hotel standards and distance rules are gates checked before anything is booked, paid or sent. Out-of-envelope requests escalate to a human.

Payments

Bookings are paid with single-use virtual cards scoped to the exact stay and amount. Card numbers are never transcribed by hand. Operations are idempotent: retries cannot double book or double pay.

Audit trail

Every decision and action writes an immutable audit record as it happens. Evidence packs export per passenger, claim ready.

Standards alignment

Access control, change management, logging and incident response are designed in line with ISO 27001 and SOC 2 Type II control families. The audit trail is shaped by EU261 evidence requirements: if a regulator or a claim asks, the record already exists.

Data

Passenger data is minimised, scoped per disruption and processed in Europe under GDPR. See Privacy.

Reporting a vulnerability

Found something? Write to security@flighter.ai. We acknowledge within one business day and will not take legal action against good-faith research.