Security

Last updated: Pending legal configuration

This is a structural legal template. Professional legal review is required before commercial launch. Jurisdiction-specific details, legal entity information, and registered addresses must be confirmed by qualified counsel.

1. Architecture Overview

Y Marine OS is designed with security as a foundational principle. The following measures are implemented without revealing implementation secrets:

2. Role-Based Access Control

Every user is assigned a role within their Organization. Permissions are resolved server-side from role, organization membership, yacht assignments, and grants. UI-level restrictions are backed by equivalent server-side enforcement.

3. Tenant Isolation

Organizations are isolated at the database layer through row-level security. An Organization cannot read, create, update, or delete data belonging to another Organization.

4. Audit Trails

Significant actions — access grants, relationship changes, provisioning, entitlement checks, extension actions — are logged to an audit trail. Audit logs are retained according to the Data Retention Policy.

5. Credential Protection

Extension credentials are stored as hashes, never in raw form. Raw secrets are shown only once during provisioning. Passwords are never stored in plaintext.

6. Signed Integrations

External platforms connect through HMAC-signed requests with nonce-based replay protection and timestamp validation. The Extension Gateway authenticates, validates capabilities, resolves grants, and audits every action.

7. Domain Separation

Sensitive domains — financial, guest PII, crew PII, owner data, APA, billing, reseller commissions — are access-controlled independently. Access to a yacht does not automatically grant access to all domains.

8. Support Access Controls

Support staff do not have permanent invisible access. Temporary support grants require a reason, scope, and expiration. Every support access event is audited and visible to the customer.

9. Incident Handling

Pending legal configuration: Incident response procedures, notification timelines, and breach communication protocols must be documented before commercial launch.

10. Data Backups

Pending legal configuration: Backup frequency, retention, and encryption details must be confirmed.

11. Encryption

Pending legal configuration: Encryption-in-transit and encryption-at-rest details must be confirmed.

12. Certifications

Y Marine OS does not claim certifications such as ISO 27001 or SOC 2 unless formally obtained and verified.

13. Contact

Pending legal configuration: Security contact information must be confirmed before commercial launch.