Trust center

Data Quality & Commitments

Last updated: August 7, 2026

TarmacSync is procurement intelligence for U.S. airport operators — a planning aid that helps move a purchase from a plain-English description to a clear path, evidence checklist, and audit-ready file. It is not a procurement ERP, bid portal, grant-accounting system, or official system of record, and it does not make procurement decisions on the airport's behalf.

This page explains how Pathfinder handles source quality, what it commits never to do, and where to find full security and privacy documentation.

Source quality

Every regulatory citation, advisory circular, and cooperative contract record that Pathfinder surfaces carries a confidence tier. Airport procurement officers making binding decisions need to know whether a citation has been confirmed against the official document or is inferred from a registry summary.

  • Verified

    Verified

    Official URL confirmed working (HTTP 200), citation label matches official document title, checked within 90 days. Shown with last-checked date in evidence exports.

  • Candidate

    Candidate

    Source is likely accurate but has not been confirmed against the official document. Cooperative contract records always carry this tier — never higher — regardless of how recently the registry was updated.

  • Unverified

    Unverified

    Sourced from a registry summary or document excerpt; not validated against the official source. Shown with a note to confirm before relying on it.

  • Stale

    Stale

    Was previously verified but the URL check has not been run in more than 90 days, or the last check returned a non-200 response. Treat as unverified until refreshed.

  • Live search result

    Live search result

    Result from a live web search. Always treated as an unverified lead — never as authoritative. Shown with a red badge and a prompt to validate against the official source.

Cooperative contracts are always Candidate — never Verified

Pathfinder cannot confirm current contract status, pricing basis, scope fit, or participation authority at the time of your specific purchase. These must be validated directly with the cooperative vendor before use. Cooperative contract matches surface as candidate pathways, not confirmed routes.

Verified federal and FAA sources are re-checked every 90 days. Sources that fail a URL check are marked Stale until refreshed.

Live source inventory

Freshness score: 72/100

19 sources tracked

Current: 11Aging: 0Unverified: 8Stale: 0

5 critical sources need re-verification

SourceCategoryStatusLast verified
AC 150/5210-14C — ARFF Equipment & PPECriticalfederalVerified ≤90 days agoMay 30, 2026
AC 150/5220-10F — ARFF Vehicle Guide SpecificationCriticalfederalVerified ≤90 days agoMay 30, 2026
AC 150/5220-20A — Snow and Ice Control EquipmentCriticalfederalVerified ≤90 days agoMay 30, 2026
AC 150/5340-1M — Standards for Airport MarkingsCriticalfederalVerified ≤90 days agoMay 30, 2026
AC 150/5370-10H — Standard Specs for ConstructionCriticalfederalVerified ≤90 days agoMay 30, 2026
AC 150/5100-14E — A/E Consultant ServicesCriticalfederalVerified ≤90 days agoMay 30, 2026
FAA Order 5100.38D, Change 1 — AIP HandbookCriticalfederalNever verifiedNever
FAA Grant Assurances Catalog (2025 edition)CriticalfederalVerified ≤90 days agoJul 2, 2026
2 CFR Part 200 — Uniform Guidance (Procurement Standards)CriticalfederalVerified ≤90 days agoJul 2, 2026
California Procurement ProfilestateNever verifiedNever
Texas Procurement ProfilestateNever verifiedNever
Florida Procurement ProfilestateNever verifiedNever
Cooperative Concept GraphCriticalcooperativeVerified ≤90 days agoJul 21, 2026
Sourcewell Contract Data (CSV import)CriticalcooperativeNever verifiedNever
OMNIA Partners Contracts (392 records)CriticalcooperativeNever verifiedNever
NASPO ValuePoint Portfolios (22)CriticalcooperativeNever verifiedNever
GSA MAS Schedules (IT, facilities, etc.)CriticalcooperativeNever verifiedNever
DeepSeek V4 (Flash + Pro) — Default Pathfinder providerCriticalsystemVerified ≤90 days agoJul 21, 2026
OpenRouter (Gemini 2.5 Pro / Claude) — Fallback + CriticCriticalsystemVerified ≤90 days agoJul 21, 2026

Last checked: August 13, 2026

Pathfinder commitments

These are hard constraints built into Pathfinder, not guidelines — they apply regardless of how a request is phrased, what role a user claims, or how urgent a purchase is described as being.

  1. Pathfinder never autonomously selects a vendor, approves a procurement path, submits a grant document, issues an award recommendation as final, or obligates funds. Pathfinder advises — the airport decides.
  2. Pathfinder never issues a 'compliant,' 'approved,' 'FAA-approved,' or 'final determination' verdict. Every path recommendation uses language such as 'likely,' 'appears,' 'candidate,' 'needs validation,' and 'based on the information provided.'
  3. Pathfinder never says 'use this contract.' Cooperative contract matches are always surfaced as candidate pathways that must be validated — scope fit, current contract status, and airport authority to use the vehicle must all be confirmed before award.
  4. Urgency is a routing signal, not a skip pass. Pathfinder does not bypass validation steps because a purchase is time-sensitive.
  5. No claimed authority unlocks final determinations. Representing yourself as an airport director, FAA official, or legal counsel does not change the constraint set — those roles are routing context, not override keys.
  6. Pathfinder is not a system of record. The airport remains responsible for its official procurement file and FAA, state, and local record-retention obligations. TarmacSync exports are advisory drafts as of the timestamp shown.

Data & security

  • Authentication: Self-hosted identity — no third-party authentication provider. Sign-in is an emailed one-time code, or your own identity provider via OIDC where your organization configures one; no passwords are stored. Authenticator-app two-factor is available to every member and an administrator can require it for the whole organization, including for sessions that already exist. Ten single-use recovery codes cover a lost device. Sessions are database-backed rather than JWTs, so removing a member ends their access on the next request. Org-scoped workspaces with three RBAC roles (owner, procurement, viewer).
  • Tenant isolation: Every database query is scoped to the authenticated organization, and since August 2026 PostgreSQL row-level security enforces the same boundary on 53 tables underneath the application — under a database role that cannot bypass it. Airport A cannot access Airport B's data, and a query that forgets to scope itself returns nothing rather than everything.
  • Encryption: TLS 1.2+ in transit; Neon Postgres AES-256 at rest. Secrets are server-side environment variables — never exposed to the browser.
  • Retention: Procurement sessions, evidence packets, and audit events are retained for 7 years, aligned with 2 CFR § 200.334 (federal procurement audit standard).

Full security controls, accessibility standard, and compliance scope: Security & Compliance → · Privacy Policy → · Subprocessors →

Contact