Security
Your card, encrypted and used once.
We take your card so a person can issue your ticket and charge it at that moment — never before. It is encrypted the instant you enter it, read only by the agent who issues your ticket, and destroyed after. Your security code is used once and never kept.
Plain language, no badges · updated 22 August 2026
What happens today
- Your card is encrypted the moment you enter it. It travels to us over an encrypted connection and is sealed at rest with AES-256-GCM — strong, modern, authenticated encryption. The key that unlocks it is held only in our server environment; it is never in our code or our source repository.
- Nothing is charged when you submit. There is no charge, no pre-authorisation and no pending amount on your statement. A person issues your ticket within 4–8 working hoursand takes payment at that moment. If we cannot issue, nothing is taken and the card is destroyed.
- Your security code is never retained. The CVV is shown to the issuing agent exactly once, to take the payment, and destroyed the instant it is viewed. It is not stored in the card vault — there is no security-code column there — and it is gone the moment it has done its one job.
- Only a named agent can read your card, and every look is logged. The number is decrypted only when an agent with explicit permission needs it to take payment. To see it they sign in, re-enter their password, and state a reason — and that access is written to a log that can be appended to but never edited. It is shown for sixty seconds, then re-masked.
- Your card is destroyed after it has been used. Once your ticket is issued the stored number is overwritten and cleared; if a booking is not fulfilled the card is destroyed then instead. Either way it is gone within seven days at the latest.
What we are building, and have not finished
We are stating this plainly because a security page that describes planned controls as though they were running is worse than no page at all.
- A payment provider, currently in underwriting. When it is live, card entry will move to the provider’s own hosted fields and pay-by-link — the number will go from your browser to them, and only a token will reach us. At that point we will hold even less than we do now.
- A formal PCI DSS assessment programme covering the systems that handle payment, including external vulnerability scanning and an annual assessment. We take card data today and protect it as described above; the formal, audited programme is in progress and we will say here when it is complete.
What else we hold
Passenger names and dates of birth, because an airline requires them to issue a ticket; your email and phone number, because a person has to reach you; and the itinerary you asked for. Retention periods, the call-recording notice and your access and deletion rights are on our privacy page.
The internal console that agents use is not reachable from the public internet, is restricted to named individuals who sign in, and records every action — every card reveal included — against the person who took it, in a log that can be appended to but never edited.
If someone asks you for a card by phone
Our number is +1 209 751 1333. You give your card on our website, over an encrypted connection — not by reading it aloud. If anyone contacts you claiming to be Airways Ticketing and asks you to read out card details, hang up and call us on that number. We will tell you exactly what is on your booking.
Found a problem?
Report security issues to security@airwaysticketing.com. We acknowledge within one business day, we don’t pursue good-faith researchers, and we say thank you properly.
Airways Ticketing is an independent travel agency registered in Algonquin, Illinois. This page describes what is running today and separates it from what is not. If you find a claim here that does not match what actually happens to your booking, tell us — that is a bug we want to hear about more than most.