Flight tracking display on the Icarus Jet operations desk

How We Protect Passenger and Trip Data

Passports, visas and trip details are the most sensitive things a flight department sends us. This is how the desk handles them, from the first email to secure deletion.

Owner: Satvir Singh, IT Manager · From Icarus Jet’s IT security protocols, September 2026 · Last reviewed 30 September 2026

Passenger data security

The short answer

  • Passports and IDs reach us through a secure upload link, straight into an encrypted vault. Never as an email attachment, never by WhatsApp.
  • They are stored encrypted in a zero-knowledge NordLocker business vault. The vault provider cannot read the files.
  • Only the people running your trip can see them. Access is set by role and reviewed quarterly.
  • They are deleted 30 days after the trip, securely and on record, unless a regular client asks us to keep documents on file.
  • Every request for passenger data, payments or trip changes is verified through a second known channel before we act.

How to send us passports and IDs

When a trip needs passport or visa copies, the desk creates a vault folder for that trip and sends you an upload link and a separate security code. You open the link, enter the code and drag the documents in. They are encrypted as they upload. You do not need an account, and nothing travels as an email attachment.

If a passport does arrive by email, we move it into the vault and delete it from the mailbox.

Where the documents are stored

The NordLocker encrypted vault is the only place we store passenger passports, visas and ID documents. Files are encrypted before they leave the device, and the service is zero-knowledge: NordLocker cannot see our files, even if its servers are breached. The vault uses AES-256, xChaCha20-Poly1305 and Ed25519.

Backups are encrypted too, so a lost, damaged or stolen device exposes nothing. We use business accounts only, with named owners and defined recovery keys, never personal vaults.

How a trip's data moves

  1. Trip request. You email the trip details to our operations inbox.
  2. Trip ID. A unique ID, for example TRF-1234, goes on every file and email for the trip.
  3. Team assigned. A dedicated trip support team manages every stage.
  4. Secure documents. Passports and visas upload straight into the encrypted vault.
  5. Operations. Permits, handling, fuel, hotels and transport are tracked against the Trip ID.
  6. Team coordination. Every change is recorded in the trip record.
  7. Operational files. Confirmations and invoices sit in role-restricted company Shared Drives.
  8. Close and delete. Identity documents are deleted 30 days after the trip, or kept for regular clients with their consent.

Who can see what

RoleTrip informationOperational documentsPassports and visas
Operations managerFullFullFull
Trip coordinatorFullFullOnly if the trip requires it
AccountsFullInvoices onlyNo access
MarketingNo accessNo accessNo access
IT administrationAdministrativeAdministrativeOnly when necessary

Access is assigned through role groups and reviewed quarterly by managers.

Email, WhatsApp and shared files

  • Email. The Trip ID goes in every subject line, every account has 2-step verification, and passports are never forwarded internally.
  • WhatsApp. Quick coordination only. Never passports, visas, IDs or payment cards, no approval held only in a chat thread, and every change is logged to the trip record straight away.
  • Shared files. Company-owned Shared Drives, never personal folders. External sharing is off by default, downloading, copying and printing are limited on sensitive drives, and audit logs are reviewed regularly.

The people and devices behind it

Every member of the team has an individual account with multi-factor sign-in, and there are no shared logins. Passenger data is handled on company-managed laptops and phones with full-disk encryption, kept up to date, with a VPN on every connection, including hotel and airport Wi-Fi. Passenger documents are never saved, downloaded or synced to a local system, a lost device can be wiped remotely, and when someone leaves, their access is removed the same day.

How long we keep passport copies

We collect only what the trip needs. Documents are viewed in the vault rather than downloaded, and any temporary copies are removed once they have been processed. Staff access ends when the trip closes. Passport and visa copies are then held encrypted for 30 days and securely erased, with the deletion logged. Regular clients can ask us to keep their documents on file, and we do that only with their consent.

How to check a request really comes from us

Our rule: any request for passenger data, payments or trip changes is verified through a second known channel before we act. It works in both directions.

  • We ask for passports only through our secure upload link, never by email or WhatsApp.
  • We never change bank details by email alone. If our payment details ever appear to change, call the desk on +1 888 277 7203 before you pay.
  • We confirm unusual requests by calling back a number we already hold, and we treat urgency and pressure as a warning sign.
  • Requests are matched to known contacts on file, and new senders and lookalike addresses are treated with suspicion.

If something goes wrong

Suspicious sign-ins are monitored continuously, audit logs and sharing are reviewed monthly, and access to every system is reviewed quarterly. If an incident happens, we detect it, contain it by revoking sessions, resetting credentials and wiping devices, inform affected clients promptly, restore from encrypted backup, and fix the root cause so it cannot happen the same way again.

Questions

Data questions flight departments ask the desk

How do I send passport copies to Icarus Jet?

Through the secure upload link the desk sends for your trip, with a separate security code. Open the link, enter the code and drag the files in. They are encrypted into our vault as they upload, and you do not need an account. Please do not send passports by email or WhatsApp.

Can I send passports by email or WhatsApp?

Please do not. WhatsApp is for quick coordination only, and we never accept passports, visas, IDs or payment cards there. If a passport does arrive by email, we move it into the encrypted vault and delete it from the mailbox, but the upload link is the safe route.

Where are passenger documents stored?

In a NordLocker business vault, the only place Icarus Jet stores passports, visas and ID documents. Files are encrypted before they leave the device, using AES-256 and xChaCha20-Poly1305, and the service is zero-knowledge, so the provider cannot read them even if its servers are breached.

How long do you keep passport and visa copies?

Thirty days after the trip is completed. The copies are then securely erased and the deletion is logged. Regular clients can ask us to keep documents on file for future trips, and we do that only with their consent.

Who at Icarus Jet can see my passengers' documents?

The operations manager, and the trip coordinator when the trip requires it. Accounts and marketing have no access to passports or visas, and IT administration only when necessary. Access is assigned through role groups and reviewed quarterly.

How can I tell a request really comes from Icarus Jet?

We verify every request for passenger data, payments or trip changes through a second known channel, and we ask you to do the same. We only ask for passports through our secure upload link, and we never change bank details by email alone. If in doubt, call the desk on +1 888 277 7203.

Questions about how we handle your data?

Ask the desk. We can walk your flight department through the process before your first trip.

Contact Us