SOC 2 Type II
Planned
SOC 2 Type II is the assurance framework we are pursuing for security, availability, and confidentiality controls relevant to our service. Status: Planned. No SOC 2 report is available yet.
Trust & Security
Aerial Ledger handles drone detection data that may support legal proceedings. Our engineering and process choices prioritize integrity, access control, and clear accountability. Status labels below are accurate as of publication. We do not claim certifications we have not completed.
We treat security and compliance as product requirements, not afterthoughts. Controls are designed so records remain attributable, auditable, and protected through retention and legal hold workflows. Marketing language does not override operational reality: every claim on this page carries an explicit status.
Planned
SOC 2 Type II is the assurance framework we are pursuing for security, availability, and confidentiality controls relevant to our service. Status: Planned. No SOC 2 report is available yet.
Designed to support CJIS requirements
Our controls are designed to support CJIS Security Policy requirements when handling Criminal Justice Information for agency customers. There is no CJIS certification. Agencies remain responsible for their own CJIS obligations.
Planned
We align our information security management system design to ISO/IEC 27001. Status: Planned. We do not claim ISO 27001 certification at this time.
Engineering and process practices
We implement engineering and process practices aligned with digital evidence handling guidance, including concepts from NIST SP 800-86 and ISO/IEC 27037. This is not a certification.
FIPS 140-validated cryptography in transit and at rest
Data is protected with FIPS 140-validated cryptographic modules in transit and at rest where applicable. Exact module inventory is maintained internally and available to qualified customers under NDA.
Detection events from third party sensors are ingested into records intended to support later review. Our practices include:
These practices are intended to support authentication readiness concepts associated with Federal Rules of Evidence 901 and 902. Admissibility outcomes depend on case facts, counsel, and the court.
Data in transit is protected using TLS with FIPS 140-validated modules where applicable. Data at rest is encrypted using FIPS 140-validated cryptography where applicable. Key management follows cloud provider and application controls reviewed during customer diligence.
Aerial Ledger receives drone detection sensor data from a third party sensor vendor. That vendor is a data source and, where applicable, a subprocessor for detection telemetry. Cloud infrastructure providers support hosting and storage.
Report suspected vulnerabilities or security concerns to security@aerialledger.com. Include steps to reproduce, affected URLs or components, and your contact information. Please allow a reasonable time for assessment before public disclosure.