Routespring Logo
Request Demo

Security at Routespring

Airlines trust Routespring with crew schedules, personal data, lodging workflows, and payment operations. That trust is the product. This page explains how we protect it.

Certifications and audits

SOC 2 Type II audited

Routespring undergoes SOC 2 Type II audits. The latest report is available under NDA for qualified customer and procurement reviews.

ISO/IEC 27001:2022 certified

Routespring maintains an ISO/IEC 27001:2022 certified information security management system. Certificate details are available to qualified procurement and security teams during vendor review.

How we protect crew data

Crew travel data is different from ordinary corporate travel data. A pairing file can reveal where crew members are expected to be, travel, and rest. Routespring treats that data with the sensitivity it deserves.

Encryption in transit

Information you submit is encrypted in transit using Secure Socket Layer (SSL) technology.

Restricted access

Personal data is kept behind secured networks and is accessible only by a limited number of authorized personnel with specific access rights.

Infrastructure and availability

Infrastructure and availability are reviewed with qualified enterprise customers during procurement and security review.

Application security

Independent penetration testing

Our systems are regularly tested by independent third-party penetration testing firms. Summary reports are available on a confidential basis.

Vulnerability scanning

Our systems are scanned on a regular basis for security holes and known vulnerabilities.

Privacy and compliance

Data Processing Addendum and privacy documentation

Routespring supports enterprise privacy review with a standard Data Processing Addendum and privacy documentation.

Subprocessors

A current subprocessor list is available during qualified procurement and security review.

Report a vulnerability

To report a potential security issue, contact Routespring through the security documentation request form and mark the message as a vulnerability report.

Report a vulnerability

Get the documents

Procurement, IT, security, and legal teams can request relevant documentation during vendor review.

SOC 2 Type II report

Available under NDA for qualified reviews.

Penetration test summary

Available on a confidential basis.

Data Processing Addendum

Standard DPA available for enterprise review.

Security questionnaire responses

Written responses provided during procurement review.

Request security documentation