PartsAndPlanes.com LLC
Security and Data Protection
Most security pages are adjectives. This one is specifics, because the people who use this platform quote government contracts for a living and can tell the difference. Everything below describes how the platform is built and operated today. Where we do not do something, this page says so.
Last reviewed: September 10, 2026
Your password
Passwords are hashed with bcrypt before they are stored. Bcrypt is deliberately slow and salts every hash, so two people with the same password produce different stored values and an attacker cannot precompute results. We never store your password and we cannot read it or recover it, which is why a reset sends you a one-time code rather than your old password. If you sign in with Google, we never receive a password at all.
Your session
When you sign in, the platform issues a signed token carried in a cookie marked HttpOnly, Secure and SameSite=Lax. HttpOnly means JavaScript on the page cannot read it, which blunts the most common way sessions get stolen. Secure means it is only ever sent over an encrypted connection. SameSite limits its use to requests originating from our own site. The token is signed with a random secret unique to this installation, held in the server environment and present in no source file, so a token cannot be forged from anything published or shared. Tokens expire, and signing out invalidates the cookie.
Multi-factor authentication: not yet
We do not currently offer MFA on sign-in, and we are not going to claim otherwise. Password resets use a one-time emailed code, and API access uses separate revocable keys rather than your password, but the sign-in itself is a single factor today. Optional TOTP-based MFA is on the roadmap; when it ships, this paragraph changes.
Encryption in transit
Every connection to partsandplanes.com and to our API is TLS. We serve TLS 1.2 and TLS 1.3 only, with TLS 1.0 and 1.1 disabled outright, using forward-secret ECDHE key exchange with AES-GCM or ChaCha20-Poly1305. Certificates are issued by Let's Encrypt and renewed automatically. HTTP Strict Transport Security is sent with a one-year lifetime including subdomains, so browsers refuse to talk to us unencrypted even if a link says otherwise. Responses also carry X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy headers.
How the servers are isolated
The host runs a default-deny firewall. Three ports are reachable from the internet: SSH, HTTP and HTTPS, and HTTP exists only to redirect to HTTPS. The database, the cache and the search cluster are bound to the loopback interface and are not routable from outside the machine at all; there is no public database endpoint to attack. The application server itself is blocked at the packet-filter level from the public interface, so every request must arrive through the reverse proxy where the TLS settings, rate limits and security headers above are enforced.
Administrative access is by SSH public key only. Password authentication is disabled entirely, so there is no password to guess or phish. The operating system installs security patches automatically.
Keeping automated attacks out
Requests are rate limited per source address and concurrent connections are capped. Failed logins, credential-stuffing attempts and probes for known vulnerable paths trigger automatic firewall bans, escalating to a week for anything scanning for configuration files or admin panels that do not exist here. Commercial scrapers are blocked by user agent while legitimate search engine crawlers are explicitly allowed, because your listings should be findable by buyers and invisible to competitors' data harvesters. Sign-up and login are protected by Google reCAPTCHA, verified server-side against Google rather than trusted from the browser.
Your documents and photos
Uploaded documents such as certifications, trace paperwork and verification records are stored privately, not on a public URL. When you or an authorized counterparty needs to view one, the platform generates a signed link that expires, with a hard ceiling of one hour. Listing photographs you intend to be public are stored publicly on purpose. Nothing else is.
Payments
Card data never touches our systems. Payments are handled by Stripe, and there is no column anywhere in our database for a card number, expiry or security code: not encrypted, not tokenized, not at all. We hold a Stripe customer reference and a subscription status. If our database were stolen tomorrow, it would contain no payment instrument belonging to anyone.
API keys and webhooks
API keys are shown to you exactly once, at creation. We store only a SHA-256 hash and a short non-secret prefix so you can tell your keys apart. Nobody here, ourselves included, can retrieve an existing key; a lost key is revoked and replaced, never recovered. Keys carry scopes and a daily call quota, record when they were last used, and can be revoked instantly. Outbound webhooks are signed with HMAC-SHA256 so your endpoint can verify a delivery genuinely came from us and was not altered in transit.
Backups and recovery
The database is backed up every night in a format that supports selective restore, not just full replacement. Each backup is verified immediately after it is taken by reading its table catalog back, because a truncated backup looks fine until the day you need it. Copies are written to separate object storage in addition to the server, encrypted at rest by the storage provider, and retained for forty-five days. Server configuration is captured alongside the data, and full machine images are taken daily.
Once a week we restore the most recent backup into a scratch database and count rows to prove the restore path works. A backup nobody has ever restored is a hope, not a backup.
Who can see your data
PartsAndPlanes is deliberately a small operation and administrative access is limited to the owner. There is no offshore support desk with a shared login and no third-party contractor with standing access to production. Your inventory, pricing and RFQ history are yours: we do not sell your data, and we do not expose your quotes or your customer relationships to other members. Market statistics shown on the platform are derived from public government award data and from aggregated activity that cannot be traced back to an individual seller's quotes.
Export-controlled and classified material
This is a commercial marketplace, not an approved repository for controlled technical data. Do not upload ITAR- or EAR-controlled drawings, technical data packages, source control drawings, or anything marked CUI, FOUO or classified. We host part numbers, NSNs, descriptions, condition, quantity, pricing and commercial certifications. Where a government solicitation carries a technical data package, we link to the government source rather than mirroring it. If you believe controlled material has been uploaded, tell us and we will remove it.
What we do not claim
We are not SOC 2 audited. We are not FedRAMP authorized. We are not a covered defense contractor system and we do not assert NIST SP 800-171 compliance. Those are meaningful, expensive certifications and pretending to hold one would be worse than not holding it. What we do claim is on this page, and every sentence of it describes something actually configured on our servers. If a certification becomes a requirement for work you want to do here, tell us: that is useful information.
Reporting a vulnerability
If you find a security problem, we want to hear about it directly and quickly. Write to [email protected] with enough detail to reproduce it. We will acknowledge within two business days and keep you informed until it is resolved. We will not pursue legal action against anyone who reports a vulnerability in good faith, who does not access or modify data belonging to other members, and who gives us a reasonable chance to fix the issue before publishing. We do not currently pay bounties, but we will credit you if you would like us to.
Security questions from prospective members, prime contractors and contracting officers are welcome and get answered by a person who knows the answer.
PartsAndPlanes.com LLC, 70 Meridian RD, Ladys Island, SC 29907