Cybersecurity
We have implemented three various levels of cybersecurity
Baseline Security
Belli's infrastructure is built on a security-first stack. We use Cloudflare for network protection and DDoS mitigation, Google IAM for identity and access management, AWS Backup for automated and reliable data recovery, and Bitwarden for enterprise credential management. Every layer of our stack is chosen with security and resilience in mind.

Advanced Security
Belli supports on-premise and private cloud deployments for airlines that require full control over their data environment. We are currently undergoing ISO 27001 certification, with comprehensive audit logging built into the platform so every action is traceable, reviewable, and compliant with your internal governance requirements.

Military Grade Security
Belli undergoes regular third-party penetration testing and independent security audits, including a security audit conducted with Tesla. Our infrastructure is protected by CrowdStrike Falcon, giving our airline partners confidence that their data is secured to enterprise standards.

Cybersecurity features
Dedicated VPC + Region
Customer data is hosted in a specific AWS region (e.g., UAE) within isolated VPCs using separate DBs, IAM, and policies.
Role-Based Access Control
General top-level access control of admins (create & edit users), members (created & edit data), and agents (limited).
Audit Logging
All edits (e.g., flight weights, AWB fields) are logged with timestamps and user ID for 30 days.
Backup & Disaster Recovery
7-day daily backups with multi-region storage allow full system recovery in case of failure, loss, or breach.
Incident Response Plan
Predefined procedures for breaches or incidents, including partner notification and recovery timelines.
Vendor Risk Management
Regular reviews of third-party tools (e.g., Clerk, AWS) for compliance and security posture.
GDPR Compliance
We support manual data requests and deletion for compliance with EU privacy regulations (DSRs, consent, export, removal).
Encryption in Transit
All user input (e.g., AWBs, cargo info) is encrypted using TLS 1.2+ to prevent interception between browser and backend.
Encryption at Rest
All cargo data (AWBs, flights, weights) is encrypted using AES-256 while stored in our databases.
SOC 2 Type II
Pending SOC 2 Type II certification via Vanta
