Security & Compliance

Security Posture & Compliance

GateReady is built with security-first architecture. This page documents our current security posture, compliance roadmap, and data handling practices for government evaluation.

Current Security Posture

Security controls currently implemented and operational across the GateReady platform.

Transport Security

  • HTTPS enforced on all endpoints (HSTS with 1-year max-age)
  • TLS 1.2+ for all data in transit
  • X-Powered-By header removed
  • Content Security Policy (CSP) headers enforced
  • X-Frame-Options: DENY (clickjacking prevention)
  • X-Content-Type-Options: nosniff
  • Source maps disabled in production

Data Encryption

  • AES-256 encryption at rest (PostgreSQL / Supabase)
  • bcrypt password hashing with appropriate cost factor
  • JWT session tokens with HMAC-SHA256 signing
  • Secure cookie attributes (HttpOnly, Secure, SameSite)

Access Control

  • Role-based access control (RBAC) — User, Admin, Enterprise roles
  • NextAuth v4 authentication framework
  • Credential-based authentication with bcrypt
  • Google SSO integration (OAuth 2.0)
  • API key authentication for B2B endpoints
  • Rate limiting on all public endpoints
  • Session timeout and token expiration policies

Audit & Logging

  • Comprehensive audit logging for all administrative actions
  • Data ingestion pipeline logging with source attribution
  • API usage tracking per key with daily aggregation
  • Alert event history with full delivery tracking
  • Source failure tracking for adapter health monitoring
  • Data anomaly detection and logging

Data Classification

GateReady processes and stores unclassified data with CUI-ready controls.

UNCLASSIFIEDCurrent classification level

All data processed by GateReady is publicly available airport security checkpoint wait time information. No classified, sensitive, or restricted government data is ingested, stored, or transmitted by the platform.

CUI-READYAspirational capability

GateReady's security architecture is designed to support Controlled Unclassified Information (CUI) handling requirements. While current data is entirely unclassified, the platform's access controls, encryption, and audit logging are built to meet NIST 800-171 requirements for CUI protection.

Data Types Processed

Airport security checkpoint wait times

Terminal and checkpoint identifiers

Lane type classifications (General, PreCheck, CLEAR)

Historical wait time patterns

Anomaly and threat pattern detections

Aggregated status snapshots

Infrastructure — US-Only Hosting

All GateReady infrastructure is hosted within the United States. No data leaves US jurisdiction.

ComponentProviderRegionDetails
Application LayerVercelUS RegionsServerless functions and edge network. All compute runs on US-based infrastructure. Automatic HTTPS with managed TLS certificates.
DatabaseSupabase (PostgreSQL)US-East-1 (N. Virginia)Managed PostgreSQL with automatic backups, point-in-time recovery, AES-256 encryption at rest, and connection pooling via PgBouncer.
AuthenticationNextAuth v4US (Vercel)Self-hosted authentication. Credentials stored in our database with bcrypt hashing. JWT sessions with configurable expiration. No third-party auth data storage.
Email DeliveryResendUSTransactional email for alerts, OTP verification, password resets, and onboarding sequences. No marketing data shared with provider.
DNS & CDNVercel Edge NetworkUSDNS resolution and content delivery via Vercel's global edge network with US-based origin servers.

Monitoring & Resilience

Continuous monitoring, automated anomaly detection, and multi-layer failover ensure uninterrupted service.

24/7 Automated Health Checks

Continuous health monitoring of all 50 airports every 5 minutes. Automated alerts when any airport data goes stale or adapters fail.

Anomaly Detection

Machine-driven detection of data spikes, dropouts, flatlines, format changes, and coordinated checkpoint closures (DARK GATE detection).

Circuit Breakers

Automatic isolation of failing data sources after 3 consecutive failures. Prevents bad data from propagating through the system.

Multi-Source Failover

3-way failover architecture for data ingestion (primary, secondary, tertiary). Ensures continuous operation even during infrastructure disruptions.

Data Quality Contracts

5-layer data quality safety net: hard reject at persistence, gate check at snapshot, consistency enforcer, accuracy audit, and freshness monitoring.

Cross-Source Validation

Real-time comparison of observations from multiple independent data sources per airport. Confidence ratings assigned based on source agreement.

Incident Response

GateReady's crisis detection and response system is designed for aviation security scenarios.

1

Detection

Automated crisis detection engine monitors for coordinated disruptions across airports. Named threat patterns (CASCADE, DARK GATE, SURGE FRONT) are identified within 15 minutes of onset.

2

Assessment

When a crisis is detected, the system automatically assesses severity, identifies affected airports, and switches to crisis mode — querying ALL available data sources rather than first-wins cascade.

3

Response

Crisis banners deployed automatically to relevant pages. Affected users receive alerts via email and push notifications. Intelligence briefings generated for enterprise customers.

4

Recovery

Continuous monitoring validates when conditions return to normal. Crisis events are not resolved until verified through independent news sources. Full post-incident documentation maintained.

Privacy & Data Protection

GateReady is committed to responsible data handling and user privacy.

No PII Sharing

GateReady does not sell, share, or distribute personally identifiable information to third parties. User data is used solely for delivering the checkpoint intelligence service.

CCPA Compliant

GateReady complies with the California Consumer Privacy Act (CCPA). Users can request data export, deletion, and opt-out of data processing through documented channels.

Data Retention

Checkpoint observation data is retained indefinitely for historical analysis and pattern detection. Status snapshots are pruned after 7 days. User account data is retained for the duration of the account and can be deleted on request.

Minimal Data Collection

GateReady collects only the data necessary to deliver its service: email address, optional screening type preference, watched airports, and saved trips. No biometric data, no location tracking, no device fingerprinting.

Accessibility

GateReady is working toward WCAG 2.1 AA compliance.

In Progress

WCAG 2.1 Level AA

GateReady is actively working toward WCAG 2.1 Level AA compliance. Current implementations include semantic HTML structure, keyboard navigation support, alt text for informational images, and sufficient color contrast ratios. A formal accessibility audit is planned as part of our compliance roadmap.

  • Semantic HTML5 structure with proper heading hierarchy
  • Keyboard-navigable interface elements
  • Color contrast meeting WCAG AA minimum ratios
  • Responsive design for mobile and assistive devices
  • ARIA labels on interactive components

Security Assessment Inquiries

We welcome security questionnaires, SSP requests, and CISO briefings. Contact our security team to begin your evaluation.