IATA AHM/IGOM Compliant

Tarmac operations.
Cockpit precision.

GHOST unifies passenger handling and flight-handling workflows in one auditable, offline-capable, cryptographically sealed platform — built for ramp agents, ops managers, and compliance auditors.

Zero-trust RBAC
Four-tier access with invisible Global Admin overwatch.
Field-ops ready
Voice-to-data, offline sync, and predictive entry.
Sealed compliance
Every operation ends in a hashed, QR-verified PDF.
Platform

Ground handling, engineered like avionics.

Every module is built to the same standard as the aircraft it serves.

Unified handling
One platform for passenger service and flight-handling — no more parallel spreadsheets or disconnected radios.
Cryptographic seals
Every turnaround produces a signed, hashed record. Auditors verify with a QR scan.
Role-aware UX
Ramp agents see the ramp. Ops managers see the ops board. Compliance sees the trail.
Offline-first (Optional — based on request)
Airside connectivity is unreliable. GHOST records locally and reconciles when the link returns.
IATA AHM/IGOM aligned
Workflows track industry standards so audits stop being emergencies.
Immutable audit trail
Every action, timestamp, and operator captured in a tamper-evident log.
Compliance

Certifications & Backend Security

Operational standards for the ramp, and enterprise-grade cloud infrastructure certifications for the data behind it. Hover any badge for a plain-language brief.

Operational Standards
IATA AHM
Airport Handling Manual

Operational workflows aligned to AHM ground-handling standards.

IATA IGOM
Ground Operations Manual

Procedures traceable to IGOM turnaround and safety practices.

Cloud Infrastructure & Third-Party Attestations
AWS-Hosted Infrastructure certification badge
AWS-Hosted Infrastructure
Tier-1 Cloud Provider

Deployed on Amazon Web Services regions with multi-AZ redundancy, encrypted EBS volumes, and VPC-isolated networking.

SOC 2 Type II certification badge
SOC 2 Type II
AICPA Trust Services

Underlying platform is independently audited against Security, Availability, Confidentiality, and Privacy criteria.

ISO/IEC 27001 certification badge
ISO/IEC 27001
Information Security Mgmt

Backend infrastructure certified to the international standard for information security management systems.

PCI DSS Level 1 certification badge
PCI DSS Level 1
Payment Card Industry

Hosting layer is validated at the highest PCI merchant level should GHOST modules ever process card data.

GDPR Aligned certification badge
GDPR Aligned
EU Data Protection

Data residency, subject-access, and right-to-erasure workflows aligned to EU General Data Protection Regulation.

HIPAA-Ready certification badge
HIPAA-Ready
Healthcare Data Controls

Infrastructure supports HIPAA Business Associate Agreements for handling passenger medical or PRM data.

Independent Attestation

Audited by an accredited third-party assessor.

Our hosting provider's SOC 2 Type II and ISO/IEC 27001:2013 controls are audited annually by A-LIGN, LLC, an independent AICPA-registered CPA firm and ISO-accredited certification body. A redacted copy of the current Attestation of Compliance is shown here.

  • Audit period covers 12 rolling months
  • Signed by A-LIGN Chief Executive and Chief Audit Officers
  • Full attestation letter available under NDA on request
Attestation of Compliance — SOC 2 Type II and ISO/IEC 27001:2013 issued to the cloud hosting provider by A-LIGN, LLC (independent third-party assessor).
Third-party Attestation of Compliance · Illustrative
How Your Data Is Protected
Encryption in transit & at rest
TLS 1.3 on every request. AES-256 encryption for database volumes and object storage.
Row-Level Security
Every table protected by RLS policies — a compromised token cannot exfiltrate another operator's records.
Point-in-time recovery
Continuous WAL backups. Any record restorable to any second within the retention window.
Isolated tenancy
Dedicated database schema per deployment. No shared query planner, no noisy-neighbour risk.
Regional data residency
Choose the AWS region your data lives in — EU, US, Middle East, or Africa endpoints available.
Immutable audit log
Every mutation captured with actor, timestamp, and cryptographic hash — tamper-evident by design.
Security

Zero-trust by construction.

Four-tier RBAC with invisible Global Admin overwatch. Every keystroke is signed, every export is sealed, every session is scoped.

  • Field agent · scoped to assigned flights
  • Ops manager · station-wide command
  • Auditor · read-only signed export
  • Global Admin · silent overwatch
Evaluator Access

Test the live GHOST platform.

Evaluators, stakeholders, and prospective partners — sign in to explore the operations console in a live environment.

Contact

Talk to the flight deck.

Request a demo, brief us on your station, or ask a compliance question. Every message goes straight to the ops team.

Phone / WhatsApp
+1 954 379 7393