Security
Last updated: Pending legal configuration
This is a structural legal template. Professional legal review is required before commercial launch. Jurisdiction-specific details, legal entity information, and registered addresses must be confirmed by qualified counsel.
1. Architecture Overview
Y Marine OS is designed with security as a foundational principle. The following measures are implemented without revealing implementation secrets:
2. Role-Based Access Control
Every user is assigned a role within their Organization. Permissions are resolved server-side from role, organization membership, yacht assignments, and grants. UI-level restrictions are backed by equivalent server-side enforcement.
3. Tenant Isolation
Organizations are isolated at the database layer through row-level security. An Organization cannot read, create, update, or delete data belonging to another Organization.
4. Audit Trails
Significant actions — access grants, relationship changes, provisioning, entitlement checks, extension actions — are logged to an audit trail. Audit logs are retained according to the Data Retention Policy.
5. Credential Protection
Extension credentials are stored as hashes, never in raw form. Raw secrets are shown only once during provisioning. Passwords are never stored in plaintext.
6. Signed Integrations
External platforms connect through HMAC-signed requests with nonce-based replay protection and timestamp validation. The Extension Gateway authenticates, validates capabilities, resolves grants, and audits every action.
7. Domain Separation
Sensitive domains — financial, guest PII, crew PII, owner data, APA, billing, reseller commissions — are access-controlled independently. Access to a yacht does not automatically grant access to all domains.
8. Support Access Controls
Support staff do not have permanent invisible access. Temporary support grants require a reason, scope, and expiration. Every support access event is audited and visible to the customer.
9. Incident Handling
Pending legal configuration: Incident response procedures, notification timelines, and breach communication protocols must be documented before commercial launch.
10. Data Backups
Pending legal configuration: Backup frequency, retention, and encryption details must be confirmed.
11. Encryption
Pending legal configuration: Encryption-in-transit and encryption-at-rest details must be confirmed.
12. Certifications
Y Marine OS does not claim certifications such as ISO 27001 or SOC 2 unless formally obtained and verified.
13. Contact
Pending legal configuration: Security contact information must be confirmed before commercial launch.