Skip to main content
SkyDynamics - home

Trust centre

What your procurement, security and compliance teams ask first.

Where the data lives, who can reach it, what happens when something breaks, and what our AI is allowed to decide. Written plainly, and limited to what we can evidence, where a certificate is not yet in hand, this page says so.

Data

Where your data lives, and who owns it

  • You own your data

    Training records, competency data and device evidence belong to your organisation. They are exportable in a structured form at any time.

  • Personal data in the EU

    Personal data is processed in Greece (EU) under the GDPR, supervised by the Greek data-protection authority.

  • Company data in Switzerland

    Commercial data, where hosted, sits under the revised Swiss Data Protection Act. The two regimes are recognised as compatible, so data moves lawfully between them.

  • On-premises and air-gapped

    Regulated and defence operators can run entirely inside their own perimeter, with no data leaving the facility.

  • Retention

    Training and qualification records are retained for the period your authority requires, and removed on request within the limits of that obligation.

  • Sub-processors

    The current list of sub-processors, with their role and location, is provided with the data processing agreement on request.

Security

How access is controlled

  • Encryption

    Encrypted in transit and at rest.

  • Role-based access

    Instructors, training standards, administrators and authorities each see only what their role requires.

  • Audit trail

    Grading, reopening, configuration changes and evidence sharing are attributable and timestamped.

  • Shared with an authority only when you say so

    Evidence reaches a competent authority when your organisation grants that access, not by default.

  • ISO 27001-aligned

    Our information security management follows ISO 27001. Where a certificate number is requested for a tender, ask us and we will state exactly what is certified and what is aligned.

  • EASA Part-IS

    Our practices are aligned with the EU information-security rules for aviation organisations, and we support customers scoping their own Part-IS obligations.

Availability

What happens when something breaks

  • Offline first where it matters

    The instructor app grades offline in the simulator and synchronises later, so a network problem never stops a training session.

  • Backups

    Backed up on a schedule agreed in your contract, with restore tested rather than assumed.

  • Support

    Support hours, response targets and escalation are set in your agreement; we would rather commit to what we can hold than publish a number.

  • Incidents

    Security incidents affecting your data are reported to you without undue delay, with what is known, what is affected and what we are doing.

Responsible AI

What our AI is, and is not, allowed to do

AeroBrain is a decision-support and analysis layer. It never holds an assessment or an operational decision.

  • The instructor assesses

    AI proposes observations from instructor notes and shows trends. The instructor confirms every entry and remains the assessor of record.

  • Reasoning is shown

    Recommendations carry the reasoning and the source behind them, so a human can agree or disagree on evidence.

  • Your data stays yours

    Customer data is not used to train models for other customers.

  • Deterministic retrieval

    Answers are grounded in your own documents and records, with the source cited, rather than generated from general knowledge.

  • Logged

    Recommendations, acceptances and overrides are recorded, so an auditor can retrace a decision.

  • Regulatory direction

    We follow the EASA AI roadmap and the EU AI Act as they apply to our products, and we do not claim certification that does not yet exist.

Accessibility

This website

  • WCAG 2.2 AA

    The site targets WCAG 2.2 AA in both light and dark themes, with keyboard access, visible focus and 44px touch targets.

  • Readable by design

    Body text from 18px, generous line height and line lengths under 70 characters: a deliberate choice for a profession that reads at altitude and at 55.

  • Reduced motion

    Animation and video respect the operating-system reduced-motion setting.

  • Tell us where it fails

    If something on this site blocks you, write to us and we will fix it and tell you when it is done.

Approvals, stated correctly

Who holds what, and why no software is "EASA certified"

This matters in a tender. Approval attaches to organisations and devices, not to the tools they use, and a supplier who blurs that is telling you something about how they will behave later.

  • The operator or ATO holds the approval

    Your organisation is approved for its training programme and procedures. That approval is yours; no supplier can hold it for you or transfer one to you.

  • The device is qualified

    An FSTD is qualified by the competent authority, on application by the operator. We build and evidence devices for that evaluation: the certificate is issued to you.

  • Software is never certified

    There is no EASA or FAA certificate for a training platform, a tech log or an EFB application. What exists is software built to the requirements your approval is assessed against.

  • What a supplier can honestly claim

    That the product is built to named requirements, that it produces the evidence your authority asks for, and that it has supported real evaluations. We claim those three, and nothing beyond them.

  • What we do for your evaluation

    Qualification evidence, QTG work, the Capability Signature record and the programme evidence, assembled so your submission stands on its own.

  • If you see "certified by EASA" on a software page

    Ask which certificate, issued to whom, with what number and scope. The answer is informative either way.

Procurement

What we can send you

Ask and we will send these directly: no form, no gate.

  • Data processing agreement

    With the current sub-processor list and transfer basis.

  • Security summary

    Controls, hosting, access model and incident process for your questionnaire.

  • Deployment options

    Managed EU hosting, on-premises or air-gapped, with what each implies for support.

  • Accreditation status

    What is certified, what is aligned and what is in progress, stated precisely.

  • Reference conversation

    A call with an operator using the product, where the customer agrees.

  • Implementation plan

    A written plan for your fleet and programme, before you commit.

Ask us the hard questions early.

Security, residency, exit and AI governance are easier to settle before a pilot project than after one.

We respond within one business day.