Built for Trust
from the Waterline Up
Y Marine OS is designed with strict access governance, tenant isolation, and auditable operations. Security is enforced server-side, not just in the UI.
Role-Based Access
Every user sees only what their role, organization, and yacht assignments permit. Permissions are resolved server-side — UI hiding is not security.
Tenant Isolation
Organizations cannot read, create, update, or delete data belonging to another organization. Row-level security is enforced at the database layer.
Audit Trails
Every significant action — access grants, relationship changes, provisioning, entitlement checks — is logged to an audit trail.
Signed Integrations
External platforms connect through HMAC-signed requests with nonce-based replay protection. Credentials are hashed, never stored raw.
Domain Separation
Sensitive domains — financial, guest PII, crew PII, owner data, APA, billing — are access-controlled independently. Yacht access does not grant all domains.
Support Access Controls
Support staff do not have permanent invisible access. Temporary support grants require a reason, scope, and expiration — and every access event is audited.
What We Do Not Claim
Y Marine OS does not claim certifications such as ISO 27001 or SOC 2 unless they have been formally obtained and verified. We do not claim compliance with GDPR, CCPA, or other regulations without professional legal review. All legal pages are structural templates pending review.
Extension Security
External platforms like Xperio3D connect through a gateway that authenticates every request, validates capabilities, resolves grants, and audits actions. Unknown credentials, capabilities, or entitlements trigger immediate rejection — fail-closed by design.
Questions about security?
Read our legal center or contact us for security-specific inquiries.