generated: '2026-07-18' method: searched source: https://www.aloft.ai/security/ standards: - id: oauth2 conforms: false evidence: No oauth2 securityScheme; the API uses an http bearer credential (Aloft Token). - id: http-bearer-auth conforms: true evidence: components.securitySchemes "Aloft Token" type http scheme bearer. - id: rfc9457-problem-details conforms: false evidence: Error responses use plain application/json, not application/problem+json. - id: pagination conforms: true evidence: Collection endpoints expose page + page_length with order_by/order. - id: idempotency conforms: false evidence: No Idempotency-Key header/parameter documented in the OpenAPI. - id: geojson conforms: true evidence: Airspace endpoints accept GeoJSON Polygon/Point/LineString features. compliance_programs: - id: soc2-type-ii name: SOC 2 Type II status: certified evidence: https://www.aloft.ai/security/ ("SOC 2 Type II - annual audit passed") - id: iso-27001 name: ISO/IEC 27001 status: certified evidence: https://www.aloft.ai/security/ ("ISO 27001 - annual audit passed") - id: faa-laanc name: FAA LAANC (approved UAS Service Supplier) status: certified evidence: https://www.aloft.ai/security/ ; FAA-approved LAANC provider