The SMS your auditor will recognise.
AviSMS runs occurrence reporting, the risk register, audits and findings, controlled documents and safety promotion for AOC holders and approved training organisations — structured the way Regulation (EU) No 376/2014, ORO.GEN.200 and ICAO Annex 19 describe a management system.
Nothing to install. Hosted in the EU. One organisation, one boundary.
Built on the regulations, not around them.
Four texts define what a safety management system in the EASA system has to do. Each one has a home in AviSMS, in the regulation's own vocabulary.
Reg. (EU) No 376/2014
Occurrence reporting, analysis and follow-up
What it requires. Mandatory occurrences reach the competent authority within 72 hours, in an ECCAIRS-compatible format. Reporters are protected by Just Culture; analysis and follow-up are documented.
Where it lives in AviSMS. A 72-hour clock on every occurrence, confidential reports whose reporter identity is stored apart from the report, an investigation record, and E5X export in the ECCAIRS 2 format.
ORO.GEN.200
The AOC holder's management system (Reg. (EU) No 965/2012)
What it requires. Lines of accountability, a safety policy, hazard identification and risk management, trained personnel, documented processes and a compliance monitoring function — proportionate to the size of the operator.
Where it lives in AviSMS. Each of the six components has a module: the organisation profile and Accountable Manager history, the signed policy, the risk register, training records, controlled documents, audits and findings.
ORA.GEN.200
The same management system for ATOs (Reg. (EU) No 1178/2011)
What it requires. Approved training organisations run a management system with the same components as an operator's, scaled to a flight school.
Where it lives in AviSMS. One product serves an AOC, an ATO, or an organisation that holds both certificates.
ICAO Annex 19
Safety management and the Doc 9859 risk matrix
What it requires. Safety policy and objectives, safety risk management, safety assurance and safety promotion, with a likelihood-against-severity matrix for risk assessment.
Where it lives in AviSMS. The four components map onto the modules. The 5×5 matrix, its tolerability thresholds and the Safety Performance Indicators are configured per organisation.
One occurrence, start to finish.
The states below are the ones the application enforces, in the order it enforces them. Every step is written to the occurrence's history by a server-side trigger, so the record of who did what cannot be edited from the browser.
Reported
Anyone with an account files it
A pilot, engineer or cabin crew member fills in the ECCAIRS-aligned form from any browser. The report receives a sequential reference such as OCC-2026-0031, and the reporting clock starts from the time of the occurrence, not the time of filing.
Authority report
72 hours, counted down
The countdown turns amber 24 hours before the deadline, and a daily check notifies the safety manager about anything overdue. When the report is marked as sent, the clock stops. The E5X file for ECCAIRS 2 is one click away.
Classified
ERCS severity and barriers
The safety manager assigns the severity class of the most probable accident outcome and records which barriers held, so the occurrence carries the European Risk Classification Scheme score the authority itself uses.
Investigated
Five Whys, root cause, corrective actions
The investigation lives on the occurrence: Five Whys, root cause, corrective actions and follow-up, feedback to the reporter, and forwarding to the colleagues who need to act. Suggested risks and mitigations are offered from a library keyed on the occurrence category.
On the register
Hazards, mitigations, residual risk
Hazards raised from the occurrence land on the 5×5 risk register with mitigations, owners and residual risk, and stay linked back to the report that raised them.
Closed
Archived, never deleted
Closure needs the investigation complete. The occurrence stays in the register, archived, for the monthly report, the trend analysis and the next audit.
Nine modules, one organisation.
Every write in every module is recorded in an audit log that only server-side functions can append to.
ORO.GEN.200(a)(3)
Dashboard
Safety Performance Indicators with targets and alert levels, monthly and category charts, and what is open: overdue reports, findings due, training expiring.
Reg. 376/2014 Art. 4
Occurrence reporting
ECCAIRS-aligned form, ERCS classification, the 72-hour countdown, investigation, confidential reports, attachments, E5X and PDF export.
Reg. 376/2014 Art. 13
Trends
Period analysis by category, severity, type, phase and location; 72-hour compliance; open against closed; risk score distribution.
ORO.GEN.200(a)(3)
Risk register
5×5 matrix with tolerability thresholds, mitigations with status, residual risk, links to occurrences, and a mitigation library the organisation extends.
ORO.GEN.200(a)(6)
Audits and findings
30 checklist templates (7 EASA-aligned, 23 for the Operations Manual), four-state answers with evidence, findings with Level 1, Level 2 and observation deadlines, extensions and verification.
ORO.GEN.200(a)(2), (a)(5)
Safety documentation
Controlled documents with versions — policy, manual, emergency response plan — and the signed safety policy statement.
ORO.GEN.200(a)(4)
Safety promotion
Notices with acknowledgements, so you know who has read what, and training records with expiry tracking and a 60-day warning.
Reports and export
Occurrence, monthly, risk register, audit findings and checklist PDFs; an Excel workbook; the E5X bundle; a ready-to-paste Operations Manual section.
ORO.GEN.200(a)(1)
Settings
Organisation profile and logo, Accountable Manager change history, users and invitations, reporting deadlines, risk thresholds, SPI definitions, safety policy, data management.
For the operators who answer to an authority.
AviSMS is built for organisations whose management system is inspected: the vocabulary, the references and the deadlines are the regulator's.
AOC holders
Commercial air transport operators of aeroplanes and helicopters certified under Regulation (EU) No 965/2012, from a two-aircraft air taxi to a regional fleet. The compliance monitoring checklists follow the Operations Manual structure.
Approved training organisations
Flight schools certified under Part-ORA, which must run the same management system as an operator, proportionate to their size. One safety manager and a handful of reporters is a complete setup.
Both under one certificate holder
An organisation that holds an AOC and an ATO approval runs one AviSMS organisation, with both numbers on the profile and one risk register.
Five roles, set by an administrator
A user belongs to exactly one organisation. The role is a claim on the user's sign-in token, set only by a server-side function, and the security rules enforce it on every read and write.
- Administrator
- Everything, including users, invitations and settings.
- Safety manager
- Occurrences (investigate, classify, close), risk register, audits, documents, promotion, reports; settings read-only.
- Auditor
- Audits and findings in full; read access elsewhere; no users or settings.
- Reporter
- Files reports; sees their own, broadcast and forwarded occurrences; reads documents and notices.
- Viewer
- Read-only across the organisation; no users or settings.
Where your data lives, and who can touch it.
Every design decision below exists so that an auditor's question about your records has a short answer.
Google Cloud, europe-west1 (Belgium)
The database, file storage, authentication and server-side functions are all pinned to one EU region. Nothing is replicated outside it.
One organisation, one boundary
Every record lives under your organisation. The security rules compare the organisation on the user's sign-in token with the path of the record on every read and write, so a query cannot reach another tenant's data.
An audit log users cannot edit
Every write to an occurrence, hazard, audit, finding, notice, document or training record is logged by a server-side trigger. Administrators can read the log; nobody can change it.
Archive, never delete
Occurrences, hazards, audits and findings are archived, not removed, and each carries its full history — who changed what, and when.
Confidential reports stay confidential
When a reporter marks a report confidential, the parent record shows no name. The identity is stored in a restricted sub-record that only the safety manager and administrators can read.
A check every morning
A scheduled function looks every morning for overdue 72-hour reports, findings past their deadline, training about to expire and hazards due for review, and notifies the people responsible.
Questions safety managers ask first.
- Does AviSMS replace ECCAIRS 2?
- No. ECCAIRS 2 is the European reporting system operated by EASA and the national authorities, and it is where your mandatory reports end up. AviSMS keeps your internal reporting, classification and investigation, and exports each occurrence as an E5X file — the ECCAIRS 2 exchange format — so what you send the authority is exactly what you investigated.
- Is AviSMS approved by EASA or a national authority?
- Software is not approved under these regulations; it is the organisation's management system that the competent authority accepts. AviSMS is built to the structure that Regulation (EU) No 376/2014, ORO.GEN.200 and ORA.GEN.200 describe, using their vocabulary and their deadlines. Verify acceptance with your competent authority as part of your management system documentation.
- How does the 72-hour deadline work?
- The clock starts at the occurrence date and time you enter, not when the report was filed — the conservative reading of Article 4. It turns amber 24 hours before the deadline, the safety manager is notified of overdue reports every morning, and the clock stops when the report is marked as sent to the authority.
- What happens to a confidential report?
- A reporter can mark any report confidential. The record everyone else sees carries no reporter name or email; the identity lives in a restricted sub-record readable only by the safety manager and administrators. Reporters see their own reports, broadcast reports, and reports forwarded to them — nothing else.
- Can a small ATO run it?
- Yes. ORO.GEN.200(b) and ORA.GEN.200(b) ask for a management system proportionate to the size and complexity of the organisation. A two-aircraft school runs occurrence reporting, a risk register and its audit checklist with one safety manager and its instructors as reporters, and switches the rest on when it needs it.
- Where is the data stored?
- On Google Cloud in europe-west1 (Belgium). Each organisation's data lives under its own path and is isolated by security rules; the audit log is written only by server-side functions.
- How do we start?
- Create your organisation at app.avisms.aero, which makes you its first administrator. Invite colleagues from Settings — each invitation is a link valid for seven days — and set your competent authority, your reporting deadlines and your risk thresholds. There is nothing to install.
- What does it cost?
- AviSMS is new and pricing is not yet published. Write to hi@avitracer.com or call +30 215 215 8312 with your organisation type and fleet size and you will get a quotation, not a sales call.
Start with your organisation.
Create it in a minute, invite your safety manager, file the first report. Your competent authority, deadlines and risk thresholds are all settings — and the defaults are the regulation's.