Security & Data Governance
Enterprise-grade protection designed for confidential flight itineraries
Because Passenger Name Records (PNR) contain sensitive traveler details, our infrastructure was engineered from day one on a Zero-Persistence principle. We convert raw flight data into your desired format and immediately purge the payload from execution memory.
Zero-Persistence Ephemeral Compute
Flight PNR strings are parsed strictly inside volatile RAM memory. Passenger names, passport numbers, and booking references are never written to disk, saved to databases, or archived in log files.
End-to-End TLS 1.3 Encryption
Every API request and response is protected in transit using strict Transport Layer Security (TLS 1.3) with modern cipher suites. Insecure HTTP connections are automatically redirected.
Instant API Key Rotation & Revocation
Rotate your secret API key with one click from your dashboard. Our server-side token versioning architecture instantly invalidates old keys and revoked sessions in real time.
Automated Rate Limiting & DDoS Shield
Multi-layer rate limiting protects your account against brute force and credential abuse, ensuring 99.99% continuous availability for legitimate traffic.
How We Protect Your Account & Credentials
Defense-in-depth across the application and database layers
Bcrypt Password Hashing & Salt Rounds
Account passwords are never stored in plaintext. They are salted with 10 rounds of bcrypt hashing before database storage. Passwords cannot be decrypted or retrieved by anyone, including internal staff.
Real-Time API Key Usage Telemetry
To give developers full visibility into their key activity, we record the timestamp, origin IP address, and client User-Agent on each API request. This data is displayed in your private dashboard to help detect leaked keys immediately.
Stateful JWT Session Revocation
Unlike purely stateless JWT setups, our authentication middleware enforces a token_version check. When you change your password or click Logout, all existing sessions and refresh tokens are revoked across all devices instantaneously.
Responsible Vulnerability Disclosure
We welcome responsible reports from security researchers and developers. If you discover a potential vulnerability, please email contact@appzone.in with detailed reproduction steps. We will acknowledge receipt within 24 hours.