Security is built into every layer of ShuttleOps — from the database engine to the API to the browser. Below is a transparent overview of the controls we have in place to keep your operational data safe.
We take security reports seriously. If you believe you have found a security vulnerability in ShuttleOps, please disclose it responsibly by emailing us directly. Do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate it (typically 90 days).
Please include: a description of the vulnerability, steps to reproduce, the potential impact, and any suggested fix if you have one. We will acknowledge your report within 2 business days.
Report a VulnerabilityShuttleOps uses the following trusted third-party service providers to operate the platform. All sub-processors are contractually bound to handle data securely.
| Provider | Purpose | Location |
|---|---|---|
| Supabase (AWS) | Database, authentication, file storage, and edge functions | US East (AWS) |
| AviationStack | Real-time flight tracking data for crew trip management | EU / Global |
Contact us for any security-related enquiries or concerns.
© 2026 ShuttleOps. All rights reserved.