Is this your company?Buyers are checking ForeFlight here. Claim foreflight.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Jeppesen ForeFlight has a new, centralized Trust Center. A modern destination designed to give you a complete view of our security, privacy, and compliance posture. Certifications, policies, and compliance documentation are now all in one streamlined location, built to serve you better. Visit the unified Trust Center at [trust.jepp.com](https://trust.jepp.com).
Jeppesen’s and ForeFlight’s Trust Centers have been consolidated here!Jun 2026
All certifications, policies, and compliance documentation are now in this streamlined location, built to serve you better.
Subprocessor list now publishedApr 2026
We have published the subprocessor lists for three Jeppesen ForeFlight product portfolios: - Crew Solutions (Crew Rostering/ Planning, Crew Tracking, Manpower Planning) - Flight Planning and Dispatch (Flitebrief, Dispatch, ITPS) - FliteDeck (Briefing / Aviator) The Subprocessors section of this trust center now lists all third parties engaged in the processing of personal data for these products, including purpose of engagement, location, applicable transfer mechanisms, and product scope. If you are an existing customer, the listed subprocessors reflect what is already documented in your Data Processing Agreement. Use the "Subprocessors by product" filter to view subprocessors relevant to your contracted products or the portfolio you are evaluating. If you have any questions, you can contact privacy@jepp.com.
Data security for general aviation customersFeb 2026
Statement on data security for general aviation / OEM customers.
Planning & Operations Portfolio Achieves ISO 27001 CertificationFeb 2026
The Planning & Operations ISMS has been ISO 27001 certified by BSI under certificate number IS 816525. The ISMS covers information assets throughout consulting, development, implementation, support and application hosting of Planning & Operations solutions for crew and fleet resources (exclude Flight Planning products). For further details and verification, please see the FAQ section, Resource-Information Security section and the BSI Certificate Validation Directory: https://www.bsigroup.com/en-GB/products-and-services/assessment-and-certification/validation-and-verification
This listing is partial
5/11 details · 45%
SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Other certifications
List your other frameworks (ISO 27001, HIPAA, PCI DSS) the way your trust center does.
Documents
List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is ForeFlight SOC 2 compliant?
ForeFlight is SOC 2 compliant. On SOC2C this listing is Listed.
Is ForeFlight ISO 27001 certified?
According to ForeFlight's public trust center, ForeFlight is ISO 27001 certified. On SOC2C this listing is Listed.
Can I use ForeFlight's SOC 2 for a vendor risk assessment?
Yes. ForeFlight's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is ForeFlight penetration tested?
ForeFlight hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is ForeFlight secure?
Security isn't a single yes/no, but ForeFlight is SOC 2 compliant. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does ForeFlight have a bug bounty or vulnerability disclosure program?
ForeFlight hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@foreflight.com or via a /security page (ForeFlight lists a security contact).
Who are ForeFlight's subprocessors?
ForeFlight lists 17 subprocessors on its trust center, including Amazon Web Services, Microsoft Azure, IBM Svenska AB, Keyzo IT Solutions Ltd (d/b/a Bytron), Jeppesen (Canada) ULC. Buyers use this for fourth-party risk review.
Where does ForeFlight host or store data?
ForeFlight hosts on AWS. Data residency details are on its trust center.
Where is ForeFlight's trust center or security page?
ForeFlight's trust center is at https://trust.foreflight.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
What is the Jeppesen ForeFlight Quality & Safety posture?
Jeppesen ForeFlight maintains world-class safety and quality standards that protect millions of passengers and customers worldwide, every day. Our Quality team operates an ISO 9001-certified quality management system, and we ensure comprehensive alignment and compliance with requirements from the FAA, EASA, CASA and other regulators. Through continuous audit oversight, regulatory liaison, and compliance monitoring, we provide full visibility into our certifications and compliance status for customers and regulatory stakeholders. Our Quality team ensures that every product and service meets the exacting standards required for safety-critical aviation systems. Our Safety team operates a Safety Management System conforming to ICAO Annex 19 and international standards, focusing on proactive risk identification and mitigation across Jeppesen ForeFlight products. The team maintains rigorous safety assurance protocols, including rapid incident response, customer notification, and continuous monitoring to verify that corrective actions and risk controls function as designed. Through safety risk management and systematic oversight, we identify and address potential issues before they impact operations, as well as conducting detailed root cause analyses when required. Together, Jeppesen ForeFlight's Quality and Safety teams share a singular commitment: ensuring the safety of flight crews and passengers traveling on aircraft worldwide. This integrated approach transforms regulatory compliance into operational excellence, delivering the reliability and trust that Jeppesen customers and the public demands.
What quality and safety practices do you follow?
We apply disciplined, auditable quality and safety practices across product design, development, verification and operations, including governed roles and release sign‑offs, requirements traceability, risk‑based verification, multi‑layer testing, independent audits, Continuous Integration and Continuous Deployment (CI/CD) Process, and production monitoring. Additionally, Jeppesen ForeFlight maintains a Safety and Quality Management system meeting international standards required of our customers.
Do you offer customer workshops or audit activities?
Yes. We host the annual Jeppesen Quality Audit Conference — a forum for customers, partners to review quality, safety and security practices, share lessons learned, and preview roadmaps. The marketing team sends out invites for the event once we have a confirmed date and location via Salesforce
How can I ask additional regulatory, quality or security questions?
Please send your question to [trust@jepp.com](mailto:trust@jepp.com).
What is a Letter of Acceptance (LOA)?
A database LOA is a formal letter issued by a Federal Aviation Administration (FAA) certification branch documenting that a data supplier has met the requirements prescribed in FAA Advisory Circular (AC) 20-153 Acceptance of Aeronautical Data Processes and Associated Databases, and RTCA DO-200 Standards for Processing Aeronautical Data. There are two types of LOAs. Type 1 LOAs are based on data requirements agreed upon between a data supplier and the customer with no identified compatibility with an aircraft system or equipment. Type 2 LOAs ensure compatibility of data requirements with installed systems or equipment (avionics manufacturers / application integrators). For the Type 2 LOA, data suppliers have additional requirements to ensure the database is compatible with Data Quality Requirements (DQR) necessary to support the intended function for the target equipment. In addition, data suppliers may obtain data service provider certification from other Civil Aviation Authorities. Jeppesen ForeFlight currently holds two such certifications. One from the European Aviation Safety Agency (EASA), issued as a Service Provider Certificate, and one from the Australian Civil Aviation Safety Authority (CASA), issued as a CASR Part 175 Certificate Aeronautical Data Service Provider.
What is a data supplier (provider)?
A navigation data supplier provides essential information and data that support navigation systems, including those used in aviation, maritime and land-based transportation. This data can include: - Aeronautical Information: For aviation, this includes data on airways, waypoints, airports and navigational aids (NAVAIDs). - Geospatial Data: This includes maps, terrain data, and geographic information systems (GIS) that help in route planning and situational awareness. - Regulatory Information: Updates on airspace restrictions, NOTAMs (Notices to Airmen), and other regulatory requirements. - Satellite Data: Information from GNSS (Global Navigation Satellite Systems).
What is a Data Definition Document (DDD)?
The Data Definition Document is created by Jeppesen ForeFlight and contains information on the content, format, accuracy, resolution, timeliness and quality assurance level of data. The DDD is shared with customers and can be mutually agreed upon as the expected delivered data quality. In some cases, Jeppesen ForeFlight mutually agrees to customer provided Data Quality Requirements (DQR) in lieu of the associated DDD. The current Data Definition Document (DDD) is available by contacting your Jeppesen ForeFlight account representative.
What is a Type 2 (LOA and DAT) certification?
The Type 2 certification guarantees that the data provided by the Type 1 holder integrates accurately on the end user’s hardware. Jeppesen ForeFlight delivers databases to end users on behalf of some Type 2 holders. Jeppesen ForeFlight does not alter or manipulate data we are delivering on behalf of the Type 2 holder. Jeppesen ForeFlight is simply providing the data updates over the internet via the Jeppesen Distribution Manager application or other delivery method. When performing these services, the Type 2 holder is responsible for the integrity of the data and how it functions in the compatible avionics system. FAA Type 2 LOA holders, and links to their Regulatory approvals/certificates are available below: EASA DAT Certificates are based on the EU Regulation 2017/373 and are equivalent to FAA Letters of Acceptance. Furthermore, bilateral recognition of EASA DAT and FAA LOA exists as documented in the Technical Implementation Procedures for Airworthiness and Environmental Certification. EASA DAT Certificate holders can be found on this site: EASA DAT Holders.
What is a AEL?
The Approved Equipment List (AEL) identifies the systems for which compatibility of the database has been established. The AEL is associated with a specific Federal Aviation Administration (FAA) Type 2 Letter of Acceptance (LOA) identified by the FAA assigned LOA number.
Are your EASA certificates affected by recent changes and are they still valid?
No — there are no changes to our EASA certifications. Certificates remain valid until revoked. For our certificate lists, see Resources.
Will evidence of a FAA Letter of Acceptance, EASA DAT or CASR Part 175 Certificate help satisfy IATA Operational Safety Audit (IOSA) audit requirements?
Navigation database integrity can be assured by obtaining data from a supplier accredited in accordance with approved or accepted standards of data integrity and quality. Such standards and related regulatory requirements include, but are not limited to: - RTCA/DO-200, Standards for Processing Aeronautical Data - RTCA/DO-201, Standards for Aeronautical Information - FAA Advisory Circular (AC) 20-153, Acceptance of Data Processes and Associated Navigation Databases - EASA (EU) 2017/373 requirements for providers of air traffic management/air navigation services - CASR Part 175 Aeronautical Information Management The specifications may be satisfied by an operator, in accordance with State approved or accepted methods for assuring data integrity and compatibility, such as: - Obtaining a letter of acceptance from an applicable authority stating the data supplier conforms to a recognized standard for data integrity and compatibility that provides an assurance level of navigation data integrity and quality sufficient to support the intended application, or; - The existence of operator validation processes to determine navigation data compatibility and accuracy that provide an assurance level of navigation data integrity and quality sufficient to support the intended application.
Do non-U.S. Civil Aviation Authorities accept FAA issued Letters of Acceptance?
Yes, depending on the existence of a bi-lateral or other type of agreement between the authorities that define the conditions for mutual acceptance. Currently only EASA and the FAA have such an agreement, as described in the _Technical Implementation Procedures For Airworthiness and Environmental Certification Between the Federal Aviation Administration of the United States of America and the European Union Aviation Safety Agency_. https://www.faa.gov/aircraft/air\_cert/international/bilateral\_agreements/eu/tip