Found something?
If you have found a vulnerability in this site or in software we built, email hello@sg5.ai with Security in the subject line. We will acknowledge it within two business days. Please give us a chance to fix it before you publish; in return, we will not pursue anyone acting in good faith. The same details are machine-readable at /.well-known/security.txt.
This website
- Served over HTTPS only. Plain HTTP requests are redirected.
- No cookies, no third-party scripts, no analytics. Nothing on the page talks to anyone but us.
- Fonts and every other asset are served from our own domain.
- The contact form is validated on the server, guarded by a honeypot rather than a CAPTCHA, and stores nothing: submissions travel to our inbox as email and are not kept on the site.
- Security headers are set on every response: content-type sniffing off, framing by other sites refused, referrer information limited.
- Deployed from version control. No change is made by hand on a server.
- Hosted on Vercel, which manages the underlying infrastructure and its patching.
Your data during an engagement
Most of our work touches data that belongs to a certificate holder and describes real aircraft, crews and passengers. We treat it accordingly.
- An NDA before anything operational. We sign it before you send a single record.
- The smallest useful slice. We ask for a month of requests or a year of removals — not the archive.
- Your systems first. Where we can, we work inside your accounts and your repositories, so the data never leaves your control. Where a copy is unavoidable, it lives in an account you can see into and revoke.
- Named access. Only the people working on your engagement can reach your data, and their access is removed when it ends.
- No model training. Your data is never used to train AI models — ours, a vendor’s, or anyone’s.
- Everything handed over. The repository, the cloud account, the keys: yours at the end, as our services page says. Copies we hold are deleted on request, or on the schedule your agreement sets.
How we build
The practices we hold ourselves to on every build, because an inspector may one day read the result.
- Role-based access that matches your actual organisation and OpSpecs, not a generic admin-and-user split.
- An audit trail on every state change: who, what and when.
- The software prepares, a named person approves. Nothing reaches a record of compliance without a signature.
- Secrets kept out of code and out of chat — in a secrets manager, rotated when someone leaves.
- Dependencies pinned, reviewed and updated on a schedule, not when something breaks.
- Change control documented to a standard a principal operations inspector can follow.
Questionnaires and audits
If your procurement or safety department needs a security questionnaire completed, or a specific control set mapped, send it. We would rather answer it precisely than have you guess, and we will tell you plainly where we don’t meet a requirement.
Contact
hello@sg5.ai — put Security in the subject line for anything that needs urgent attention.