Cybairsecurity
CompliAir — DO-326A Automation

From hundreds of pages to Security Objectives in seconds.

Manual DO-326A analysis costs certification programmes months of qualified engineering time. CompliAir eliminates that bottleneck — without compromising rigour or moving a single byte off-premise.

4.2s

Full DO-326A analysis

Manual equivalent: ~3.5 months

Zero

Data egress events

Fully air-gap compatible

EASA + FAA

Accepted output formats

DER-ready evidence packages

Analysis Engine

Inspect any avionics component.

The diagram shows a sample aircraft architecture. Hover any LRU to reveal its DO-326A Security Objectives, active protocol vulnerabilities, and DO-326A rule violations — in real time.

This is the same analytical lens CompliAir applies to your actual system documentation — at scale, on-premise, with full traceability to DO-326A sections.

What to look for

  • 🔴EFB — two CRITICAL violations
  • 🟠FMC — ARINC 429 + wireless exposure
  • EFIS / TCAS — unencrypted feeds
  • FMC↔EFIS — only encrypted link
complair — interactive architecture view

Hover any component
to inspect its security profile

DAL-ACatastrophic
DAL-BHazardous
DAL-DMinor
DAL-ENo Effect
Unencrypted protocol
Encrypted connection
Active violation
6 components · 6 connections · hover to inspect
DO-326A / ED-203A
Process

How it works.

Five stages from document ingestion to a certification-ready evidence package. Each step runs on-premise — no external network calls at any point.

01

Ingest your documentation

Upload system architecture documents, safety assessments, ICD specifications, and design artefacts. CompliAir processes natural language, structured tables, and technical diagrams natively.

02

LLM-driven Security Objective extraction

Our aviation-tuned LLM engine scans documentation and identifies Security Objectives as defined under DO-326A/ED-203A — mapping them to system functions, failure conditions, and affected aircraft domains.

03

Threat condition mapping

Each Security Objective is matched against a structured threat taxonomy aligned with DO-356A/ED-204A methods. Threat conditions are scored using aviation-adapted severity metrics.

04

Audit-ready report generation

CompliAir produces structured compliance evidence packages formatted to EASA and FAA DER review expectations — ready for certification submission without reformatting.

05

Closed-loop, on-premise deployment

Zero data egress. CompliAir runs entirely within your infrastructure. Certification artefacts and design documentation never traverse an external network.

Capabilities

Built for certification engineers.

Aviation-tuned LLM core

Fine-tuned on DO-326A, DO-356A, and ED-202A. Understands airworthiness security semantics — Security Objectives, threat conditions, and DAL levels — natively.

Zero data egress

Fully on-premise. Certification artefacts never leave your network. No cloud dependency, no telemetry, no licensing callbacks. Your IP stays yours.

Human oversight by design

Every AI output is flagged and requires engineer sign-off before entering a compliance record. Built to satisfy DO-326A's human-in-the-loop requirements.

Audit-ready output

Generates structured compliance evidence in EASA and FAA DER review format. Traceable to specific DO-326A sections and ED-203A clauses throughout.

Feature Overview

Automated Security Objective identification from documentation
DO-356A / ED-204A method cross-referencing
Threat condition mapping with CVSS-A scoring
Audit-ready EASA & FAA DER format output
Fully on-premise — zero data egress
Standards covered:DO-326AED-203ADO-356AED-204AED-202AARINC 429ARINC 664 / AFDXMIL-STD-1553ARINC 825
FAQ

Common questions.

More detail available during a scoped evaluation. Get in touch to arrange one.

What is DO-326A and why does it matter?

DO-326A (Airworthiness Security Process for Commercial Aircraft) is the FAA/EASA-accepted standard that makes cybersecurity a mandatory criterion of airworthiness. Without a compliant DO-326A process, new aircraft systems cannot receive type certification. Its European equivalent is ED-203A.

How does CompliAir automate DO-326A compliance?

CompliAir uses a local LLM with RAG over DO-326A/ED-203A standards to analyse aircraft system descriptions. It identifies Security Objectives, maps threat conditions, assesses DAL levels, and generates structured compliance evidence — all on-premise with zero data egress.

Does CompliAir replace a qualified cybersecurity engineer?

No. CompliAir is a reference assistant, not a decision-maker. Every AI-generated output is flagged and must be reviewed and accepted by a qualified engineer before it can enter any compliance record. This design is intentional and aligns with DO-326A's human-oversight requirements.

Can CompliAir be used in air-gapped or classified environments?

Yes. CompliAir is deployed fully on-premise. The LLM runs locally and all data — including aircraft system descriptions — remains within your network perimeter. There is no cloud dependency and no data egress.

Which standards does CompliAir cover?

CompliAir covers DO-326A, ED-203A, DO-356A (Airworthiness Security Methods and Considerations), ED-202A, and references MITRE ATT&CK for ICS threat cataloguing.

Contact

Ready to remove the DO-326A bottleneck?

CompliAir is available for NDA-protected evaluation with a limited number of certification programmes. Engagements are scoped, on-premise, and covered by NDA from day one.