Back to home
Trust & Safety

Security at MarineFly

Enterprise-grade security and compliance built into every layer of our platform. Your crew data is protected with the same rigor as the world's most demanding organizations.

Security Pillars

How we think about and implement security across our platform.

Encryption Everywhere

All data in transit is protected with TLS 1.3. Data at rest uses AES-256 encryption. Key management is handled via hardware security modules (HSMs) with automatic key rotation every 90 days.

Identity & Access

Multi-factor authentication (MFA) is enforced for all accounts. Single Sign-On (SSO) via SAML 2.0 and OIDC is supported for enterprise customers. Role-based access control (RBAC) ensures users only access what they need.

Infrastructure

Our infrastructure runs on geographically distributed, SOC 2-compliant data centers. Auto-scaling, DDoS protection, and redundant networking ensure uptime and resilience. We maintain a 99.99% uptime SLA.

Privacy by Design

Data minimization, purpose limitation, and user consent are built into our architecture. Personal data is pseudonymized where possible, and access is logged and audited continuously.

Resilience & Recovery

Automated backups are performed every 6 hours with 30-day retention. Disaster recovery plans are tested quarterly. Our RTO is under 1 hour and RPO is under 15 minutes.

Continuous Monitoring

24/7 security operations center (SOC) monitors for threats and anomalies. Automated intrusion detection, vulnerability scanning, and log analysis ensure rapid incident response.

Our Security Practices

Security is not a checkbox — it's a continuous discipline. Here are the practices that keep your data safe every day.

Annual third-party penetration testing
Quarterly internal security audits
Automated dependency vulnerability scanning
Secure software development lifecycle (SSDLC)
Background checks for all employees
Mandatory security awareness training
Incident response plan with defined playbooks
Bug bounty program for responsible disclosure

Security Report

We publish an annual security report summarizing our audit results, incident metrics, and improvements made. For enterprise customers, we provide detailed security questionnaires and architecture documentation under NDA.

Request Security Documentation

Report a Security Issue

We take all security reports seriously. If you've discovered a vulnerability, please let us know responsibly.

Responsible Disclosure

  • Provide detailed steps to reproduce the issue
  • Allow us reasonable time to investigate and remediate before public disclosure
  • Do not access, modify, or delete data belonging to other users
  • We commit to acknowledging reports within 48 hours
Report to security@marinefly.com