Security
Last updated:
Please read the Security statement below.
The Keep Good Company® LLC ("we," "us," or "our") is committed to protecting personal and sensitive information. We enforce security at every layer of the AIREPORT® platform and services (the "Services"): infrastructure, application, and operational practice. Our most recent security assessment was completed in March 2026.
Infrastructure Security
AIREPORT® runs on infrastructure that holds independent compliance certifications and defends at the network level. Our hosting infrastructure is SOC 2 Type II compliant, and our payment processing is PCI DSS Level 1 compliant. All data in transit is encrypted with TLS 1.2 or 1.3, and data at rest is encrypted with AES-256. The platform is protected by DDoS mitigation, a web application firewall, and automated bot detection and filtering, and it enforces a Content Security Policy, HTTPS-only connections, and comprehensive security headers.
Data Protection
Your portfolio data is never accessible to other users. It is used only for your own account, never for advertising, model training, or third-party purposes; usage analytics cover only the technical and interaction data described in our Privacy Policy. AI-powered features operate under zero-data-retention agreements with our service providers, so your portfolio data is never stored by those providers or used for model training. Access to sensitive data is restricted.
Authentication & Identity
Sessions are protected by cryptographically signed tokens carried in secure, HTTP-only cookies, and they expire automatically. Sign-in with Google or Apple uses OAuth 2.0 and shares only your name and email address with us; AIREPORT® stores no password for OAuth accounts. Authentication endpoints are rate limited.
Payment Security
All payment processing is handled by Stripe, a PCI DSS Level 1 certified provider. No payment card data is stored on our servers. All payment events are cryptographically verified before processing.
Privacy & Compliance
We comply with the GDPR for users in the European Union and the CCPA for California residents. The personal data we collect includes account information, portfolio data, and usage analytics, and it is stored in the United States. You have the right to access, correct, and delete your personal data, and we do not sell user data to third parties. We conduct security assessments regularly.
Third-Party Service Providers
The Keep Good Company® LLC works with service providers that maintain independent security certifications: Supabase (SOC 2 Type II) for database and authentication infrastructure; Stripe (PCI DSS Level 1) for payment processing; Loops (SOC 2 Type II) for transactional email delivery; Proton (ISO/IEC 27001) for encrypted email and file storage; and Apple iCloud (ISO/IEC 27001 and 27018) and Notion (SOC 2 Type II) for internal operations.
Data Retention & Management
Data is retained while your account is active and as needed to provide the Services, and thereafter only for the legitimate business or legal purposes described in our Privacy Policy (which also provides for aggregated or de-identified usage data to be retained for service improvement and security); verified deletion requests are honored as described there. Only authorized personnel may access user data, on a need-to-know basis, and when data is no longer needed it is securely deleted within the respective service environment.
Contact Information
Security concerns and questions about security may be directed to care@keepgood.co.
Security
Last updated:
Please read the Security statement below.
The Keep Good Company® LLC ("we," "us," or "our") is committed to protecting personal and sensitive information. We enforce security at every layer of the AIREPORT® platform and services (the "Services"): infrastructure, application, and operational practice. Our most recent security assessment was completed in March 2026.
Infrastructure Security
AIREPORT® runs on infrastructure that holds independent compliance certifications and defends at the network level. Our hosting infrastructure is SOC 2 Type II compliant, and our payment processing is PCI DSS Level 1 compliant. All data in transit is encrypted with TLS 1.2 or 1.3, and data at rest is encrypted with AES-256. The platform is protected by DDoS mitigation, a web application firewall, and automated bot detection and filtering, and it enforces a Content Security Policy, HTTPS-only connections, and comprehensive security headers.
Data Protection
Your portfolio data is never accessible to other users. It is used only for your own account, never for advertising, model training, or third-party purposes; usage analytics cover only the technical and interaction data described in our Privacy Policy. AI-powered features operate under zero-data-retention agreements with our service providers, so your portfolio data is never stored by those providers or used for model training. Access to sensitive data is restricted.
Authentication & Identity
Sessions are protected by cryptographically signed tokens carried in secure, HTTP-only cookies, and they expire automatically. Sign-in with Google or Apple uses OAuth 2.0 and shares only your name and email address with us; AIREPORT® stores no password for OAuth accounts. Authentication endpoints are rate limited.
Payment Security
All payment processing is handled by Stripe, a PCI DSS Level 1 certified provider. No payment card data is stored on our servers. All payment events are cryptographically verified before processing.
Privacy & Compliance
We comply with the GDPR for users in the European Union and the CCPA for California residents. The personal data we collect includes account information, portfolio data, and usage analytics, and it is stored in the United States. You have the right to access, correct, and delete your personal data, and we do not sell user data to third parties. We conduct security assessments regularly.
Third-Party Service Providers
The Keep Good Company® LLC works with service providers that maintain independent security certifications: Supabase (SOC 2 Type II) for database and authentication infrastructure; Stripe (PCI DSS Level 1) for payment processing; Loops (SOC 2 Type II) for transactional email delivery; Proton (ISO/IEC 27001) for encrypted email and file storage; and Apple iCloud (ISO/IEC 27001 and 27018) and Notion (SOC 2 Type II) for internal operations.
Data Retention & Management
Data is retained while your account is active and as needed to provide the Services, and thereafter only for the legitimate business or legal purposes described in our Privacy Policy (which also provides for aggregated or de-identified usage data to be retained for service improvement and security); verified deletion requests are honored as described there. Only authorized personnel may access user data, on a need-to-know basis, and when data is no longer needed it is securely deleted within the respective service environment.
Contact Information
Security concerns and questions about security may be directed to care@keepgood.co.