Skip to content

Security Overview.

Effective September 2, 2026

This page summarises how we approach security for the Nexora platform and for this website. Detailed security documentation, architecture reviews and questionnaires are available to airline and business aviation customers under NDA — ask us.

1. Isolation from aircraft systems

Nexora runs as a software overlay inside the in-flight entertainment content sandbox. It has read access to the media it captions and translates and no write access to aircraft avionics, flight systems or safety-critical infrastructure. IFE systems are already segregated from aircraft control domains by the airframe and IFE manufacturers; Nexora does not alter that segregation.

Because it cannot affect the safe operation of the aircraft, Nexora is designed to a DO-178C Level E (no safety effect) posture. We do not claim any higher design-assurance level.

2. Data handling aboard the aircraft

Captioning, translation and personalisation run on edge hardware in the cabin. Passenger speech and requests are processed and discarded; no passenger profile is exported from the aircraft. Model and content updates are applied during scheduled ground time, not in flight.

3. Encryption

Data at rest on Nexora devices is encrypted with AES-256. Data in transit between the aircraft and InovativAI systems during ground synchronisation uses TLS 1.2 or higher with mutual authentication.

4. AI safety

Conversational features (SkyChat) are constrained to flight, travel and service topics, run against curated airline content, and are tested for prompt injection and unsafe output before every release. Model outputs never trigger actions outside the IFE sandbox.

5. This website

The site is served over HTTPS behind Cloudflare, sends standard security headers, loads no third-party scripts until you consent, and validates and rate-limits contact form submissions. See the Privacy Policy for what we collect.

6. Responsible disclosure

If you believe you have found a security issue in Nexora or this website, email [email protected] with the subject “Security disclosure”. We acknowledge reports within two business days and will not take legal action against good-faith research.