Security

  1. Home
  2. ISO SOC Security

Security You Can Trust. Independently Verified

At Cirro, security isn’t just a feature; it’s the foundation. Cirro is ISO/IEC 27001:2022 certified, including codes of practice for ISO/IEC 2017:2015 (Cloud services security controls), and ISO/IEC 27018:2019 (Protecting personally identifiable information (PII) in public clouds) and demonstrates compliance with SOC 2 Trusted Services Criteria of Security, Confidentiality, Availability, and Processing Integrity Trusted Services Criteria (TSC) ,two of the most respected international standards for information security and operational controls. Compliance to these information security frameworks confirm that our systems, processes, and internal controls are independently audited and continuously monitored to protect your data, ensure platform reliability, and maintain operational integrity for aviation operators worldwide.

Our security program includes formal risk management, role-based access controls, encryption, secure software development practices, vulnerability management, incident response procedures, and continuous monitoring of critical systems. These controls are audited against the SOC 2 Trust Services Criteria for Security, Availability, and Confidentiality, and are governed under our ISO/IEC 27001 Information Security Management System (ISMS) to ensure consistent, organization-wide protection.

What this means for your operation:

  • Reduced vendor risk and simplified compliance questionnaires
  • Enterprise-grade protection for operational, safety, and personnel data
  • Confidence operating in both U.S. and international regulatory environments
  • Faster security reviews during U.S. enterprise and government procurement

For U.S. operators, government contractors, and enterprise procurement teams, these certifications simplify vendor security reviews and risk assessments while supporting requirements under FAA, Department of Transportation, and customer security programs.

For customers operating internationally, including in the EU, our controls and processes are also aligned to support GDPR obligations and cross-border data protection requirements. SOC 2 Type II compliance confirms our controls operate effectively over time, while ISO/IEC 27001 certification validates our long-term security governance framework.

Full audit reports are available under NDA upon request. If your compliance, IT, or procurement team would like to review our documentation, please contact [email protected].

Security certifications
Cirro by AirSuite
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.