1. Our approach
Compliance software occupies an awkward position. It holds the evidence that an organisation is airworthy, and it is exactly the sort of system whose compromise would matter — not because an aircraft falls out of the sky when a database is breached, but because falsified or destroyed records undermine every assurance built on them.
We design around three principles:
- The audit trail is the product. Records can be created and corrected, but the history of who did what is append-only. Integrity is treated as a higher priority than convenience.
- Least privilege by default. Permissions are modelled on post-holder structure, not on generic “admin” and “user” tiers, because that is how accountability is actually allocated in an approved organisation.
- Assume we will be audited. Not only by customers, but by their competent authorities. Everything here is written to survive that.
2. What Part-IS is
Part-IS is the European Union's information security regime for civil aviation. It requires organisations to identify and manage information security risks with the potential to affect aviation safety — a deliberately narrower and more safety-focused scope than general cybersecurity regulation. It comprises two instruments:
| Instrument | Applies to | Applicable from |
|---|---|---|
| Commission Delegated Regulation (EU) 2022/1645 Part-IS.D.OR |
Design and production organisations approved under Part-21 | 16 October 2025 |
| Commission Implementing Regulation (EU) 2023/203 Part-IS.I.OR and Part-IS.AR |
Air operators, CAMOs, Part-145 and Part-147 organisations, ATOs, aeromedical centres, ATM/ANS providers, aerodrome operators and their competent authorities | 22 February 2026 |
The organisation requirements in the two instruments follow the same structure and numbering — IS.D.OR.200 and IS.I.OR.200 both address the information security management system, and so on through to .260. Where this page cites a point, the equivalent point in the other instrument applies to organisations in its scope.
It is a management system obligation sitting alongside your SMS and compliance monitoring function, with findings, corrective actions and authority oversight attached. That is precisely why it belongs in the same system as the rest of your management system rather than in a separate security tool.
3. Why Part-IS reaches us, and what we commit to
Wingcert is not itself an approved aviation organisation. Part-IS reaches us through you, our customer, via IS.I.OR.235 — contracting of information security management activities. Where you contract out an activity relevant to your information security management, you must ensure that:
- the contracted activity complies with the requirements of the Regulation, and the contracted organisation works under your oversight;
- the risks associated with the contracted activity are appropriately managed; and
- your competent authority can have access, upon request, to the contracted organisation, to determine continued compliance with the applicable requirements.
The obligation is yours, not ours — the regulation is explicit that outsourcing an activity does not outsource accountability. But you cannot discharge it unless we cooperate. So we commit contractually, in clause 11 of the Terms, to:
- work under your oversight for the services we provide, and support your monitoring of them;
- give you the interface and architecture information you need to include us in your risk assessment under IS.I.OR.205;
- grant your competent authority — and EASA, where it acts as such — access on request, to the extent needed to determine continued compliance;
- notify you of relevant information security incidents within [24] hours, deliberately inside your 72-hour window under IS.I.OR.230; and
- flow equivalent obligations down to our own material sub-contractors.
4. Part-IS clause mapping — what we do as your supplier
Point by point, what each organisation requirement asks of you and what we provide to support it. This table is written to be pasted directly into your supplier assessment.
| Point | What it requires of you | What Wingcert provides |
|---|---|---|
| IS.I.OR.200 ISMS |
Establish, implement and maintain an information security management system proportionate to your organisation. | We operate our own ISMS covering the Service. Our policy set and scope statement are available under NDA on request. |
| IS.I.OR.205 Risk assessment |
Identify information security risks to elements with a potential impact on aviation safety, and assess them. | An interface description, data-flow diagram and architecture summary so our systems can be scoped into your assessment rather than treated as a black box. |
| IS.I.OR.210 Risk treatment |
Treat identified risks in a timely manner and verify effectiveness. | Our control set (sections 6–14 below), plus written responses to your specific treatment requirements where they concern our service. |
| IS.I.OR.215 Internal reporting |
Operate an internal reporting scheme so personnel can report incidents and vulnerabilities. | Our own internal scheme for our staff; and, in the product, a configurable internal information security reporting channel for yours (section 5). |
| IS.I.OR.220 Incidents |
Detect, respond to and recover from information security incidents. | 24/7 monitoring and alerting, a documented incident response plan, and defined recovery objectives (sections 10, 11 and 13). |
| IS.I.OR.225 Authority findings |
Respond to findings raised by your competent authority, with root cause and corrective action. | Where a finding concerns our service, we support your response with the evidence and remediation detail you need, on the timescale your authority has set. |
| IS.I.OR.230 External reporting |
Report to your competent authority any incident or vulnerability representing a significant risk to aviation safety — an initial notification as soon as the condition is known, a report within 72 hours, and a follow-up covering recovery and preventive action. | Notification to you within [24] hours of us becoming aware, with the information reasonably available, and continuing updates as the investigation develops so you can make both the 72-hour report and the follow-up. |
| IS.I.OR.235 Contracting |
Ensure contracted activities comply, work under your oversight, have their risks managed, and are accessible to your competent authority on request. | Contractual commitments in Terms clause 11, including the authority access right, audit rights, and flow-down to our sub-processors. |
| IS.I.OR.240 Personnel |
Ensure personnel are competent and, where appropriate, screened. | Background checks proportionate to role, confidentiality undertakings, and role-appropriate security training on joining and annually (section 6). |
| IS.I.OR.245 Record-keeping |
Keep records of risk assessments, treatments, incidents, training and reviews. | We retain our own information security records for [5] years; and the product provides tamper-evident, retention-configurable record-keeping for yours. |
| IS.I.OR.250 ISMM |
Document the ISMS in an information security management manual. | Document control with revision history, approval workflow and read-and-sign distribution — the ISMM is managed like any other controlled manual (section 5). |
| IS.I.OR.255 Changes |
Manage changes to the ISMS, with authority involvement where required. | Change notification for material changes to the Service that affect your risk picture, per Terms clause 11.2. |
| IS.I.OR.260 Continuous improvement |
Assess ISMS effectiveness and improve it. | Trend reporting across incidents, findings and corrective actions, and our own annual management review, summarised for customers on request. |
5. Running your own Part-IS ISMS in Wingcert
Part-IS is structurally a management system — risk assessment, treatment, internal and external reporting, findings, corrective action, records, a manual, management review. That is the same machinery Wingcert already provides for compliance monitoring and SMS. So rather than a separate module, Part-IS is configured as another framework inside the system you already run.
| Part-IS activity | Wingcert capability |
|---|---|
| Information security risk register | The risk register, scored pre- and post-mitigation, with named residual risk owners and enforced review dates |
| Risk treatment plans and verification | Corrective action workflow with owners, deadlines, escalation and a verification gate before closure |
| Internal information security reporting | The occurrence and hazard reporting channels, configured for information security, with confidential reporting supported |
| Incident register and 72-hour external reporting | Incident records with detection timestamp, a reporting clock against the IS.I.OR.230 deadline, and export in your authority's format |
| Authority findings under IS.I.OR.225 | The findings register, with root cause analysis and the same CAPA workflow used for audit findings |
| The ISMM | Document control — controlled revisions, approval by the accountable manager, read-and-sign distribution with evidence of acknowledgement |
| Personnel competence under IS.I.OR.240 | Training and qualification currency, with expiry escalation before a lapse becomes a finding |
| Records under IS.I.OR.245 | Configurable retention with an append-only audit trail across every record type |
| Continuous improvement under IS.I.OR.260 | Trend dashboards and management review packs drawn from live data |
The point is not that Part-IS needs new software. It is that running it in a separate spreadsheet, disconnected from the SMS and compliance monitoring it is supposed to sit alongside, is how organisations end up with three management systems and one auditor asking why they disagree.
6. Organisational security
- A documented information security policy set, reviewed at least annually and approved by [role].
- A named individual accountable for information security: [role/title].
- Background screening for personnel with access to production systems, proportionate to role and to the extent permitted by local law.
- Written confidentiality undertakings for all personnel and contractors, surviving the end of engagement.
- Security awareness training at induction and annually, with role-specific training for engineering and support staff.
- A documented joiners, movers and leavers process; access is revoked [within X hours] of an individual leaving.
- Disciplinary process for security policy violations.
7. Product and development security
- Peer review is required for every change to production code; no developer merges their own work unreviewed.
- Separate development, staging and production environments. Production data is never used for development or testing; test datasets are synthetic.
- Automated dependency scanning, with defined remediation targets — [critical: X days; high: Y days].
- Static analysis and secret scanning in the build pipeline; builds fail on detected secrets.
- Framework-level protections against the OWASP Top 10 — parameterised queries, output escaping, CSRF tokens, a content security policy, and secure session handling.
- Passwords stored only as salted hashes using a memory-hard algorithm. Credentials are never logged.
- Independent penetration testing [annually / at frequency X], with an executive summary available to customers under NDA. [Delete if not yet performed — do not claim this before the first test is complete.]
- Change management with rollback capability and audited deployment records.
8. Infrastructure and hosting
- Hosted in the European Union with [provider name], in [region]. Enterprise customers may specify an alternative region or private tenancy.
- Underlying data centres hold [ISO 27001 / SOC 2 / other] certification; certificates available on request.
- Encryption in transit: TLS 1.2 or higher for all connections, with HSTS enforced and modern cipher suites only.
- Encryption at rest: AES-256 for databases, object storage and backups.
- Tenant isolation: every record carries its tenant identity and is filtered at the data-access layer; isolation is covered by automated tests on every build.
- Network segmentation, with databases unreachable from the public internet.
- Managed patching of operating systems and platform components on a defined cycle, with emergency patching for actively exploited vulnerabilities.
9. Access control
- Role-based access control modelled on post-holder structure, with per-module and per-record permissions.
- Multi-factor authentication available to all customers and enforceable organisation-wide. SSO/SAML and directory provisioning on Enterprise.
- Least-privilege administrative access for Wingcert personnel; production access is limited to named individuals who require it, granted just-in-time and time-bounded where practicable.
- All administrative access to production is authenticated with MFA, logged, and reviewed [quarterly].
- Wingcert personnel do not access customer content except to provide the Service, to provide support you have requested, to investigate a security incident, or where legally compelled — and every access is written to the audit trail.
- Elevated access to confidential safety reports can be restricted to a named safety manager role, separate from ordinary administrators.
10. Logging, monitoring and detection
- An append-only application audit trail recording actor, action, object, timestamp and source address for every create, update, approve and delete.
- Infrastructure and security logs centralised, retained for [12] months, and protected against modification by the accounts that generate them.
- Automated alerting on authentication anomalies, privilege changes, unusual export volumes and error-rate spikes.
- Availability monitoring with [24/7 on-call rota / business-hours] response.
11. Incident detection, response and recovery
We maintain a documented incident response plan covering detection, triage, containment, eradication, recovery and post-incident review, tested [at least annually].
| Stage | Target | Notes |
|---|---|---|
| Triage of a suspected incident | [1] hour | From detection or report |
| Notification to affected customers | Within [24] hours | Set inside your 72-hour IS.I.OR.230 and Article 33 GDPR windows |
| Personal data breach notification | Without undue delay | Per DPA clause 6, with the Article 33(3) content so far as available |
| Interim status updates | [Every 24 hours] | Until containment is confirmed |
| Post-incident report | [10] business days | Root cause, impact, recovery and preventive actions — the input to your follow-up report |
Whether an incident meets the threshold for external reporting to your competent authority is your determination as the approved organisation. We provide the facts; you make the report. We will not report on your behalf unless you instruct us in writing.
12. Audit, assurance and competent authority access
- Customer audits. Once per twelve-month period, and additionally after an incident affecting you or where your authority requires it — see Terms clause 11.7.
- Competent authority access. We grant your competent authority, and EASA where it acts as such, access on request under IS.I.OR.235(c). This is a contractual commitment, not a discretionary courtesy, and it is not subject to the annual frequency limit.
- Documentation pack. Available under NDA: ISMS scope statement, policy summaries, architecture and data-flow description, sub-processor list, penetration test summary, business continuity summary and completed security questionnaires.
- Questionnaires. We complete customer security questionnaires as part of onboarding and at renewal.
13. Business continuity and disaster recovery
- Recovery point objective (RPO): [1] hour.
- Recovery time objective (RTO): [4] hours.
- Automated encrypted backups on a [daily] cycle with [35]-day retention, stored separately from production.
- Restore procedures tested [at least annually], with results recorded.
- The mobile field application operates fully offline, so on-site auditing continues through a platform outage; work syncs when service is restored.
- You can export your complete dataset at any time — see Terms clause 18. Continuity of your records should never depend solely on our continued existence.
14. Supplier and sub-processor management
- Sub-processors are assessed before engagement and reviewed [annually].
- Each is bound by a written contract imposing data protection obligations no less protective than the DPA, and — where material to the security of the Service — the Part-IS flow-down in Terms clause 11.4(d).
- The current list is maintained at Annex III of the DPA, with [30] days' notice of additions and a right to object.
15. Vulnerability disclosure
If you believe you have found a security vulnerability in Wingcert, please tell us at [email protected]. Include enough detail to reproduce the issue.
- We acknowledge reports within [2] business days and give a substantive response within [10] business days.
- We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service degradation, and give us reasonable time to remediate before disclosing.
- Please do not access, modify or exfiltrate data that is not your own. If you encounter customer data, stop and tell us.
- [State whether a bounty is offered, or say plainly that recognition is offered but payment is not.]
16. Certifications
“Aligned with ISO 27001” and “certified to ISO 27001” are very different claims, and buyers in this market know the difference. State the current position plainly and give a target date rather than implying more than you hold — an overclaim discovered during due diligence costs more than the certificate would have.
| Standard | Status | Target |
|---|---|---|
| ISO/IEC 27001 | [Aligned, not certified] | [Target date] |
| SOC 2 Type II | [Not held] | [Target date or “no current plan”] |
| GDPR | Compliance programme in place; see Privacy Notice and DPA | — |
| Part-IS supplier support | Contractually committed under Terms clause 11 | — |
17. Contact
Data protection: [email protected]
Documentation pack and questionnaires: [email protected]