At Aloft, we take nice pleasure within the safety of our merchandise and group. In partnership with Anzu Robotics, we’ve launched Air Management for the Raptor. This product has been constructed over the past twelve months to safeguard your knowledge and allow safe flight. We engaged White Knight Labs, a famend third-party cybersecurity agency, to conduct a complete penetration check to make sure that the Anzu Raptor meets the best safety requirements. Because the previous saying goes, “With nice energy comes nice accountability,” so we additionally needed to make sure that buyer knowledge was all the time encrypted with communications solely to Aloft servers.
In constructing and designing the Raptor flight expertise, we needed to carry ahead one of the best parts of the {hardware} and firmware offered within the licensed expertise whereas making a essentially higher and extra empowered flight expertise. For instance, we eliminated the geofencing so there isn’t any spurious geofencing or blocking of your flights with Raptor drones.
White Knight Labs examined and validated these core knowledge parts of their evaluation. With the default setup with Aloft operating out of the field, your knowledge is safe and stays solely within the Aloft Air Management platform.
What’s Static and Dynamic Evaluation of Site visitors?
White Knight Labs utilized static and dynamic evaluation methodologies to evaluate the safety of the Anzu Raptor and Air Management software. These methodologies contain analyzing the system’s code and habits in a managed surroundings to determine vulnerabilities or weaknesses.
Static Evaluation includes reviewing the supply code, configuration information, and system structure with out executing the code. By meticulously analyzing the static parts of the Anzu Raptor, White Knight Labs can determine any potential safety flaws within the design and implementation levels.
Dynamic Evaluation includes observing the system in operation, analyzing the info visitors, and monitoring the drone’s habits in real-time. By executing the system in a reside surroundings, White Knight Labs can determine vulnerabilities that solely grow to be obvious throughout precise use. Particularly, we needed to check your entire lifecycle of the Raptor, from preliminary registration to takeoff, touchdown, pictures, and flight logs.
The White Knight Labs Evaluation
White Knight Labs is very regarded within the cybersecurity trade for its static and dynamic visitors evaluation experience. Their staff of seasoned professionals employed trendy info safety instruments and strategies to scrutinize the info circulation of Anzu Raptor, coming from the Anzu Raptor, and talk with the Aloft Air Management software and servers.
1. Knowledge Transmission Targets: One of many main issues for this expertise is the safety/vacation spot of knowledge transmission. White Knight Labs meticulously analyzed the info circulation from the Anzu Raptor and confirmed that every one knowledge was solely being despatched to Aloft servers. This verification ensures that no delicate info was noticed being leaked or intercepted by unauthorized events.
2. References to Chinese language Domains: Throughout their evaluation, White Knight Labs recognized a number of references to Chinese language domains throughout the system, though no knowledge was flowing to them. Aloft promptly remediated these findings by eradicating the references, additional enhancing the safety of our platform. This proactive measure underscores our dedication to sustaining a safe and reliable product.
The Significance of Third-Social gathering Attestation
Partaking a good third get together like White Knight Labs offers an extra layer of assurance for our clients. Their thorough and unbiased analysis of the Anzu Raptor validates our dedication to knowledge safety. By remediating findings and guaranteeing that every one knowledge is securely transmitted to encrypted Aloft servers, now we have bolstered the integrity and reliability of the Raptor+Aloft platform. We consider that safety wants transparency and bringing in outdoors events for evaluation is the easiest way to trust in our platform.
Whereas Aloft undergoes annual SOC 2 Kind II and ISO 27001 safety certifications, together with FAA audits as an authorized UAS Service Provider for LAANC, we frequently endure third-party analyses and penetration exams. Working with suppliers like White Knight Labs will proceed to be a core a part of our course of for our airspace, UTM, fleet administration, and {hardware} integrations.
Conclusion
The profitable penetration check performed by White Knight Labs is a major milestone for the Anzu Raptor. It demonstrates our unwavering dedication to delivering a safe and dependable product. At Aloft, we perceive the significance of belief and safety in at present’s digital panorama. By partnering with main cybersecurity consultants and repeatedly enhancing our safety measures, we goal to offer our clients with peace of thoughts, figuring out that their knowledge goes precisely the place they intend it to.
Our vigilance doesn’t cease with this report. As with something in safety, it’s an iterative and ongoing course of. We are going to proceed to enhance the platform’s posture within the coming weeks, months, and years. For any firmware updates or product expansions with Anzu, we’ll be conducting related and ongoing analyses to make sure that your knowledge stays safe, encrypted, and solely on US-based Aloft servers always.
If you need a replica of the attestation letter or wish to talk about the Anzu+Aloft product in additional element, please e mail infosec@aloft.ai.
