Aerial Ledger

Trust & Security

Security and compliance posture

Aerial Ledger handles drone detection data that may support legal proceedings. Our engineering and process choices prioritize integrity, access control, and clear accountability. Status labels below are accurate as of publication. We do not claim certifications we have not completed.

Philosophy

We treat security and compliance as product requirements, not afterthoughts. Controls are designed so records remain attributable, auditable, and protected through retention and legal hold workflows. Marketing language does not override operational reality: every claim on this page carries an explicit status.

Compliance status

SOC 2 Type II

Planned

SOC 2 Type II is the assurance framework we are pursuing for security, availability, and confidentiality controls relevant to our service. Status: Planned. No SOC 2 report is available yet.

CJIS Security Policy

Designed to support CJIS requirements

Our controls are designed to support CJIS Security Policy requirements when handling Criminal Justice Information for agency customers. There is no CJIS certification. Agencies remain responsible for their own CJIS obligations.

ISO/IEC 27001

Planned

We align our information security management system design to ISO/IEC 27001. Status: Planned. We do not claim ISO 27001 certification at this time.

Evidence integrity practices

Engineering and process practices

We implement engineering and process practices aligned with digital evidence handling guidance, including concepts from NIST SP 800-86 and ISO/IEC 27037. This is not a certification.

Encryption

FIPS 140-validated cryptography in transit and at rest

Data is protected with FIPS 140-validated cryptographic modules in transit and at rest where applicable. Exact module inventory is maintained internally and available to qualified customers under NDA.

Evidence integrity

Detection events from third party sensors are ingested into records intended to support later review. Our practices include:

These practices are intended to support authentication readiness concepts associated with Federal Rules of Evidence 901 and 902. Admissibility outcomes depend on case facts, counsel, and the court.

Data handling and privacy summary

Encryption statement

Data in transit is protected using TLS with FIPS 140-validated modules where applicable. Data at rest is encrypted using FIPS 140-validated cryptography where applicable. Key management follows cloud provider and application controls reviewed during customer diligence.

Subprocessors and data sources

Aerial Ledger receives drone detection sensor data from a third party sensor vendor. That vendor is a data source and, where applicable, a subprocessor for detection telemetry. Cloud infrastructure providers support hosting and storage.

Security contact and responsible disclosure

Report suspected vulnerabilities or security concerns to security@aerialledger.com. Include steps to reproduce, affected URLs or components, and your contact information. Please allow a reasonable time for assessment before public disclosure.