Skip to content
farel-logo
Security & compliance

Security your airline can audit

PCI DSS v4.0.1 service-provider compliant. Hosted on Google Cloud in Frankfurt. Externally penetration-tested every year.

  • Schema-isolated per airline
  • Card data never stored
  • PNRGOV over MQ and VPN, not FTP
  • Weekly security releases
Farel security architecture: passengers, agencies, staff, and third-party systems enter through Cloud Armor and a global HTTPS load balancer into Cloud Run services across three zones in Google Cloud europe-west3 (Frankfurt), backed by regional-HA PostgreSQL with a synchronous standby and Cloud KMS customer-managed keys

Where airline software security breaks

Most PSS platforms were built before cloud zones, bot traffic, and supply-chain attacks were the threat.

Batch sync, batch failure

When one vendor's overnight sync breaks, every airline on the platform wakes up with stale inventory and no check-in.

Shared credentials, shared breach

Common admin logins and long-lived API keys mean one leaked credential exposes every carrier's PNRs.

Plaintext regulatory traffic

PNRGOV, PAXLST, and APIS still move over FTP and aging SITA links at most carriers.

Bots blocking inventory

Speculative holds, OTP pumping, and scripted account creation sit on the booking funnel and nobody measures them.

Isolated by schema, scoped at the door

Isolated by schema, scoped at the door

Each airline has its own PostgreSQL schema and database role. Every API request is scoped to the airline at authentication, and users, configuration, and audit logs are partitioned per carrier.

A dedicated Google Cloud project, database, and service set is available for airlines that require full physical separation.

What runs underneath

Controls in production today.

Cloud architecture

Google Cloud europe-west3. Application services on Cloud Run across multiple zones behind a global HTTPS load balancer. Infrastructure-as-code for every service, database, and network rule.

Encryption

AES-256 at rest with Google-managed keys; payment platform keys customer-managed in Cloud KMS. TLS 1.2 or higher on all external traffic and on every service-to-database connection. Card data tokenized; no PAN stored.

Network defense

Cloud Armor WAF and DDoS protection with a threat-prevention profile on production and daily reporting in front of the payment platform. Internal traffic stays inside a private VPC with no public exposure.

Identity & access

SSO and MFA on every human and vendor account. Named accounts only, no shared logins. Least-privilege IAM roles that auto-expire and recertify every six months. Session tokens in HttpOnly cookies, not browser storage. The airline can suspend any user immediately from the admin panel.

Secure development

Mandatory peer review on every merge. Daily Semgrep SAST and dependency vulnerability scanning on every repository. Behavioral malware scanning, install-script lockdown, and dependency pinning on every package install. Strict CSP and security-header baseline on all web apps.

Vulnerability management

Monthly patching. Quarterly external ASV scans and internal vulnerability scans, semi-annual segmentation testing, and annual internal, external, and application penetration tests by an independent third party under the PCI cycle.

PNRGOV, PAXLST, APIS - over MQ and VPN, not FTP

PNRGOV, PAXLST, APIS - over MQ and VPN, not FTP

Regulatory traffic moves through IBM MQ inside VPN tunnels to each authority. Manifests and advance passenger data leave the platform encrypted, on schedule, and auditable end to end.

Adding a new border authority when you open a route is configuration, not a project.

Bots don't get to block your seats

Bots don't get to block your seats

Cloudflare Turnstile gates booking creation and OTP delivery. Every airline runs monitor-first, then enforce, with a daily abuse digest and an audit log of every rate-limit decision.

Stops speculative holds, OTP pumping, and scripted account creation before inventory is touched.

Zone failure recovers in under 15 minutes. Automatically

Zone failure recovers in under 15 minutes. Automatically

PostgreSQL runs in regional high availability with a synchronous standby in a second zone - RPO near zero, RTO under 15 minutes on zone loss.

Daily backups with 7-day point-in-time recovery, stored in EU multi-region storage separate from the primary instance. Regional failure: restore into another region, up to 24 hours.

Frankfurt by default. In-country where the law requires it

Frankfurt by default. In-country where the law requires it

Production runs in Google Cloud europe-west3, Frankfurt, under EU data protection.

Where local regulation requires in-country residence, we mirror to local infrastructure with no break in encryption or feature parity.

Compliance & assurance

What is held today and what is planned - kept apart on purpose so nothing reads as more than it is.

Current
  • PCI DSS v4.0.1

    Service-provider level, assessed annually by an independent QSA. 2026 assessment completed August 2026; Attestation of Compliance issuing. Scope reduced to SAQ A through processor-hosted card fields.

  • Independent penetration testing

    Internal, external, and application tests, most recent July-August 2026. Executive summaries shareable under NDA.

  • GDPR and CCPA

    Documented retention schedules. Data Processing Addendum available to every customer.

    Read the DPA
  • People

    Annual security awareness and secure-development training for all staff. Background checks on hire.

  • Full data portability

    API, scheduled export, or full database dump at any time. No exit or extraction fees.

Planned 2026-2027
  • Formal backup restoration test

  • Container image scanning and CI security gate blocking critical findings

  • Extended alerting on cloud audit events and authentication anomalies

  • SOC 2 Type II

    Timeline shared on request.

  • ISO 27001

    Timeline shared on request.

Trust & transparency

What you can request or read today, and what is still being built.

Available

Penetration test summary

Executive summary of the most recent internal, external, and application tests, shared under NDA.

Request via email
Available

Sub-processors list

Every third party that processes customer data on Farel's behalf, with location and purpose.

View the list
Coming

Status page

Public uptime and incident history for the platform.

Coming

Vulnerability disclosure

Report a security issue by email today. A formal disclosure programme is in preparation.

Report an issue

FAQ

Before your security review

Answers to the questions we hear most from airline IT and compliance teams.

Production runs in Google Cloud europe-west3 (Frankfurt) under EU data protection, across multiple zones in a single region; a zone failure recovers automatically in under 15 minutes, and cross-region recovery is a restore from backup into another region. Where local regulation requires in-country residence, we mirror to local infrastructure with no break in encryption or feature parity - scope it with us during procurement so the environment is in place before go-live.
Each airline has its own PostgreSQL schema and database role, every API request is scoped to the airline at authentication, and users, configuration, and audit logs are partitioned per carrier. Airlines that require full physical separation can run in a dedicated Google Cloud project, database, and service set.
No. Card data is captured in processor-hosted fields and tokenized; no PAN ever touches Farel servers. That keeps the platform in SAQ A scope, assessed annually by an independent QSA.
Not yet. Both are on the roadmap and neither is held today. We hold PCI DSS v4.0.1 at service-provider level, assessed annually by an independent QSA, and share the current timeline for SOC 2 and ISO 27001 on request.
Yes. The executive summary of the most recent internal, external, and application penetration tests (July-August 2026) is available under NDA. Contact us and we will share it with your security team.
Yes. API, scheduled export, or a full database dump at any time, with no exit or extraction fees and nothing withheld.

Everything your airline needs, in one place

From inventory to check-in, see how each module fits together to streamline your airline operations

Inventory & Pricing

Optimize every seat, maximize every flight

Manage seat availability, fare structures, and revenue logic across all distribution channels.

Inventory & Pricing

Security questions before procurement?

Book a working session with our security team on your compliance, residency, and integration requirements.