Built to outlast us. Verified by anyone.
Every entry is hash-chained, every mechanic is validated against the FAA Airmen Registry, and everything is encrypted at rest and in transit, then backed up across two providers. And if Yolog ever folds, you get 180 days’ notice and a complete export whose hash chain you can verify without us.
How we keep your records untamperable, recoverable, and yours.
Tamper-evident chain
Each entry's SHA-256 hash includes the prior entry's hash. Edit one entry — even a single space — and every following hash breaks. Buyers, FSDOs, and auditors can verify the chain themselves.
Live FAA cert validation
Every mechanic's certificate number is checked against the FAA Airmen Registry at the moment they sign. Expired, suspended, or invalid certs cannot lock an entry. The validation result is part of the entry record.
Encryption everywhere
AES-256 at rest, TLS 1.3 in transit. Mechanic certificate numbers and other PII are additionally encrypted at the field level, under a key held in our secrets manager — separate from the database, so a stolen database row reads as ciphertext.
Survivability commitment
If Yolog ceases operations, you receive at least 180 days’ written notice and a complete export in PDF and CSV. Every export carries each entry’s hash and the hash before it, so the chain’s integrity can be recomputed with nothing but a SHA-256 library — your records outlast us. Spelled out in our Data Processing Agreement.
Every entry inherits the one before it.
Tampering with any entry breaks every entry that follows. This is the same idea that secures Bitcoin, applied to your maintenance log.
Two providers. Separate keys. Versioned.
Storing aircraft records in one place under one key would be malpractice. Here's how we actually do it.
Live record store
Managed PostgreSQL in a US region. AES-256 at rest, point-in-time recovery, and TLS required on every connection.
Documents & scans
POH, 337s, weight & balance, insurance, and scanned logbook pages. Versioned and server-side encrypted; a SHA-256 of each file is recorded in Postgres.
Weekly off-site dump
A weekly logical Postgres dump to a separate bucket, encrypted under a different key than the live database. One key compromise doesn't lose everything.
PII held apart
Mechanic cert numbers and other PII are application-encrypted under a key kept in the secrets manager, never written to the database in the clear.
In-transit encryption
TLS 1.3 with HSTS preload, and TLS required between the app and Postgres. No plaintext on the wire, anywhere.
Check it without us
Every CSV and PDF export carries each entry's hash and the hash before it. Anyone with a SHA-256 library can recompute the chain and confirm nothing was altered.
What Yolog does for which regulation.
Yolog is a record-keeping aid. The legal primary record is your paper book. Here's how the digital record maps to the regs that matter.
What we haven’t done yet — and won’t pretend we have.
An audit badge you can’t verify is just a sticker. Here’s where independent assurance honestly stands today.
Want the technical detail?
We’re glad to walk through the hash-chain construction, key handling, and continuity plan, or hand your security team the specifics. Just ask.