Palladium holds safety occurrences, compliance findings and crew records. Before you put that data anywhere, you are entitled to plain answers about how it is handled. These are ours.
Every AOC runs on its own instance. This is not a shared database with row-level permissions separating operators — it is a separate deployment, scoped to your AOC from the day it is set up.
The practical consequence is the one that matters at audit: another operator's breach cannot expose your occurrence data, because your records were never in the same place. Neither can a permissions error, a misconfigured query, or a support engineer looking at the wrong tenant.
If we host it for you, instances are in Europe.
You are not obliged to let us. Palladium runs on your own server or your own cloud account just as well, in which case the hosting, the jurisdiction and the access are entirely yours and we hold nothing. The server requirements are published so your IT team can judge that for themselves.
Instances are backed up daily. Records are retained for five years, which covers the retention periods an operator is normally working to for occurrence and compliance records.
Your records are yours. A full export is available on request and delivered encrypted. There is no charge for it and no notice period attached to it — it is not a lever we use to keep customers.
These are in Palladium today, not on a roadmap:
If your IT or security colleagues need detail this page does not cover, ask us directly and we will answer specifically rather than sending a brochure. We would rather have that conversation before you buy than after.
Bring your security questionnaire to the demo. We will go through it with you on the call rather than returning it three weeks later.
Last reviewed 30 August 2026.
We would rather lose a deal on an honest answer than win one on a vague brochure.
We read every enquiry personally and reply within one business day. If we are not a fit, we will tell you.