PNR Converter Logo
PNR Converter
Back to Home

Security & Data Governance

Enterprise-grade protection designed for confidential flight itineraries

IATA & GDPR Data Privacy Compliance

Because Passenger Name Records (PNR) contain sensitive traveler details, our infrastructure was engineered from day one on a Zero-Persistence principle. We convert raw flight data into your desired format and immediately purge the payload from execution memory.

Zero-Persistence Ephemeral Compute

Flight PNR strings are parsed strictly inside volatile RAM memory. Passenger names, passport numbers, and booking references are never written to disk, saved to databases, or archived in log files.

End-to-End TLS 1.3 Encryption

Every API request and response is protected in transit using strict Transport Layer Security (TLS 1.3) with modern cipher suites. Insecure HTTP connections are automatically redirected.

Instant API Key Rotation & Revocation

Rotate your secret API key with one click from your dashboard. Our server-side token versioning architecture instantly invalidates old keys and revoked sessions in real time.

Automated Rate Limiting & DDoS Shield

Multi-layer rate limiting protects your account against brute force and credential abuse, ensuring 99.99% continuous availability for legitimate traffic.

How We Protect Your Account & Credentials

Defense-in-depth across the application and database layers

Bcrypt Password Hashing & Salt Rounds

Account passwords are never stored in plaintext. They are salted with 10 rounds of bcrypt hashing before database storage. Passwords cannot be decrypted or retrieved by anyone, including internal staff.

Real-Time API Key Usage Telemetry

To give developers full visibility into their key activity, we record the timestamp, origin IP address, and client User-Agent on each API request. This data is displayed in your private dashboard to help detect leaked keys immediately.

Stateful JWT Session Revocation

Unlike purely stateless JWT setups, our authentication middleware enforces a token_version check. When you change your password or click Logout, all existing sessions and refresh tokens are revoked across all devices instantaneously.

Responsible Vulnerability Disclosure

We welcome responsible reports from security researchers and developers. If you discover a potential vulnerability, please email contact@appzone.in with detailed reproduction steps. We will acknowledge receipt within 24 hours.