Docs
SECURITY

Zero Production Data Required

Flightline is designed from the ground up to never touch your production data. Here's how we keep your data safe.

How It Works

We analyze your schema structure to generate synthetic test data. Your actual customer data stays exactly where it is, in your environment.

DATA FLOW
YOUR ENVIRONMENT
Your Schema
Structure only
Your CI/CD
GitHub, GitLab, etc.
Your Data
Never leaves
FLIGHTLINE
Generate Tests
100% synthetic
Run Analysis
No PII processed
Return Results
Pass/fail only
Your production data never leaves your environment. Ever.

Security Principles

Data Minimization

We only process schema structure, never actual customer data. If we don't have it, it can't be breached.

Your Environment

Flightline runs as a CLI in your CI/CD pipeline. Data stays in your infrastructure.

Synthetic by Design

All test data is generated synthetically based on your schema. Zero PII by construction.

Encrypted in Transit

All communications between your environment and Flightline are encrypted with TLS 1.3.

Audit Logging

Clear audit trail of what Flightline accessed and when. Exportable for compliance.

Minimal Retention

We minimize what we store and give you control over retention policies.

What We Don't Do

Security is as much about what you don't do as what you do.

Access your production databases
Store customer PII
Require broad access to your codebase
Train models on your proprietary data
Share data between customers

Compliance

SOC 2 Type II
Security & availability controls
DESIGNED FOR
HIPAA
Healthcare data protection
DESIGNED FOR
GDPR
EU data protection
COMPLIANT BY DESIGN

Because Flightline never processes PII, we're GDPR-compliant by design. SOC 2 and HIPAA certifications are on our roadmap as we scale.

Have Security Questions?

We're happy to walk through our security architecture with your InfoSec team, complete security questionnaires, or discuss specific compliance requirements.