Security at Routespring
Airlines trust Routespring with crew schedules, personal data, lodging workflows, and payment operations. That trust is the product. This page explains how we protect it.
Certifications and audits
SOC 2 Type II audited
Routespring undergoes SOC 2 Type II audits. The latest report is available under NDA for qualified customer and procurement reviews.
ISO/IEC 27001:2022 certified
Routespring maintains an ISO/IEC 27001:2022 certified information security management system. Certificate details are available to qualified procurement and security teams during vendor review.
How we protect crew data
Crew travel data is different from ordinary corporate travel data. A pairing file can reveal where crew members are expected to be, travel, and rest. Routespring treats that data with the sensitivity it deserves.
Information you submit is encrypted in transit using Secure Socket Layer (SSL) technology.
Personal data is kept behind secured networks and is accessible only by a limited number of authorized personnel with specific access rights.
Infrastructure and availability
Infrastructure and availability are reviewed with qualified enterprise customers during procurement and security review.
Application security
Our systems are regularly tested by independent third-party penetration testing firms. Summary reports are available on a confidential basis.
Our systems are scanned on a regular basis for security holes and known vulnerabilities.
Privacy and compliance
Data Processing Addendum and privacy documentation
Routespring supports enterprise privacy review with a standard Data Processing Addendum and privacy documentation.
Subprocessors
A current subprocessor list is available during qualified procurement and security review.
Report a vulnerability
To report a potential security issue, contact Routespring through the security documentation request form and mark the message as a vulnerability report.
Report a vulnerabilityGet the documents
Procurement, IT, security, and legal teams can request relevant documentation during vendor review.
SOC 2 Type II report
Available under NDA for qualified reviews.
Penetration test summary
Available on a confidential basis.
Data Processing Addendum
Standard DPA available for enterprise review.
Security questionnaire responses
Written responses provided during procurement review.