Answers for the board member who asks how safe this is
Passkeys instead of passwords, permissions re-checked on the server, data kept to your own club, and an audit trail when a member gets locked out.
Passkeys
Face ID, Touch ID, and Windows Hello sign-in with no username to type: the device or browser picks the account for you. Register a passkey from Profile → Security and add one for every device you actually carry: a phone, a laptop, a hangar iPad. A password still works as a full fallback for anyone who'd rather not use one. Underneath, a sign-in challenge expires in five minutes and is cleared out by the nightly cleanup if it is never used, and a successful sign-in starts your session through a one-time link that is created and used entirely on the server. It never reaches the browser.
Signing in on the ramp with cold hands, in a category where most platforms still ship a 2010 login form.
- Passkeys
Sign in on the ramp with cold or greasy hands: genuinely modern sign-in.
Permissions that are actually enforced
Every change your club makes goes through code that works out who is signed in and which organization is active on the server, not on whatever the browser happens to believe. Where an operation is restricted to a role, that check runs again on the server before anything is written.
Hiding a button is decoration. The request underneath still has to clear the same check on the server, whether or not a member could ever click it.
Organization isolation
Club data (reservations, flight logs, squawks, maintenance, members, and billing) is read and written through the member's active organization, so a pilot who belongs to two clubs never sees the wrong club's data on a screen meant for the other one. Content that comes from Centerline itself, such as help articles and release announcements, is deliberately shared across every club instead.
The audit log
Member lockouts, unlocks, and nightly maintenance runs are recorded to an audit log with who did it, what happened, which record it touched, and any relevant details. It's a Centerline-support tool today rather than a report your officers run themselves: when a member says they were locked out and nobody remembers why, our support team can pull up exactly what happened and when.
Member lockout
Suspending a member for non-payment or a lapsed currency doesn't require deleting their history. Locking a membership blocks access to that organization at the server (the same authorization check every dashboard page runs, not something the browser is trusted to do) and shows as a lock icon on that member in the user list, with an optional message explaining why. A locked-out member lands on a dedicated page that shows that message and gives them a way out: switch to another club they belong to, or go to their own profile. It's a suspension, not a ban, and lock and unlock actions land in the audit log described above.
Under the hood
A few defenses that don't need a headline of their own. Text a member types (names, descriptions, comments, resolutions) is treated as plain text, not as code, before it goes into a notification email, so anything pasted or malicious arrives as harmless characters instead of running in someone's inbox. Formatted text a member composes for the notification bell is cut down to a short list of safe formatting the moment it's saved, not just when it's displayed. Fuel receipt photos are uploaded by Centerline rather than straight from the browser, and handed back only through a link that expires, never a public one. And signup can require a challenge to keep the member list free of bots.
Access, roles and compliance
Passkeys are listed with the rest of what governs who gets into your club: the five roles, invitations, member notes, lockout, and the currency tracking that decides who may book.
See every member and access featureBring it to your next board meeting
60 days free, no credit card. Long enough to satisfy the most careful member of your board.
Start your free trial60 days free. No credit card required.