Security at MarineFly
Enterprise-grade security and compliance built into every layer of our platform. Your crew data is protected with the same rigor as the world's most demanding organizations.
Security Pillars
How we think about and implement security across our platform.
Encryption Everywhere
All data in transit is protected with TLS 1.3. Data at rest uses AES-256 encryption. Key management is handled via hardware security modules (HSMs) with automatic key rotation every 90 days.
Identity & Access
Multi-factor authentication (MFA) is enforced for all accounts. Single Sign-On (SSO) via SAML 2.0 and OIDC is supported for enterprise customers. Role-based access control (RBAC) ensures users only access what they need.
Infrastructure
Our infrastructure runs on geographically distributed, SOC 2-compliant data centers. Auto-scaling, DDoS protection, and redundant networking ensure uptime and resilience. We maintain a 99.99% uptime SLA.
Privacy by Design
Data minimization, purpose limitation, and user consent are built into our architecture. Personal data is pseudonymized where possible, and access is logged and audited continuously.
Resilience & Recovery
Automated backups are performed every 6 hours with 30-day retention. Disaster recovery plans are tested quarterly. Our RTO is under 1 hour and RPO is under 15 minutes.
Continuous Monitoring
24/7 security operations center (SOC) monitors for threats and anomalies. Automated intrusion detection, vulnerability scanning, and log analysis ensure rapid incident response.
Our Security Practices
Security is not a checkbox — it's a continuous discipline. Here are the practices that keep your data safe every day.
Security Report
We publish an annual security report summarizing our audit results, incident metrics, and improvements made. For enterprise customers, we provide detailed security questionnaires and architecture documentation under NDA.
Request Security DocumentationReport a Security Issue
We take all security reports seriously. If you've discovered a vulnerability, please let us know responsibly.
Responsible Disclosure
- Provide detailed steps to reproduce the issue
- Allow us reasonable time to investigate and remediate before public disclosure
- Do not access, modify, or delete data belonging to other users
- We commit to acknowledging reports within 48 hours