Our Security Principles
- Least-privilege access. Role-based access control (RBAC) with per-user authentication means people see only the data and actions their role requires, across office and vessel.
- Encrypted in transit. Ship-shore synchronisation and office access are designed to run over encrypted channels, so data is protected as it moves between vessel and shore.
- Everything is auditable. Actions are logged with user, time and change detail, giving a defensible trail for internal audit, ISM and vetting.
- Resilient by architecture. The vessel works fully offline and reconciles automatically — no reliance on a live link means no data loss and no exposure window during outages.
- Controlled documents. The Document Management module distributes controlled, versioned SMS documents with read-receipts, reducing the risk of out-of-date procedures at sea.
Alignment with IMO Cyber-Risk & the ISM Code
Since 1 January 2021, IMO Resolution MSC.428(98) requires cyber risk to be addressed within a company's Safety Management System under the ISM Code. Volaxin is designed to support that obligation rather than complicate it:
- Access control and authentication that map to your cyber-risk policy.
- Audit logging that evidences "who did what, when" for DPA reviews and PSC.
- Controlled SMS document distribution so cyber and safety procedures reach the vessel and are acknowledged.
- Offline-first design that keeps critical operations running if connectivity is degraded or lost.
Volaxin is a tool that supports your cyber-risk framework; it does not replace your own SMS, policies or crew training. We're happy to map our controls to your risk assessment during evaluation.
Data Handling & Privacy
We treat customer and crew data as a responsibility, not just an asset:
| Area | Approach |
|---|---|
| Data ownership | Your operational data remains yours; we act as a processor for the purpose of delivering the service. |
| Access | Role-based, least-privilege, per-user — with administrative access restricted and logged. |
| Personal data | Crew and personal data handled with privacy-by-design principles and data-subject rights in mind. |
| Hosting & regions | Cloud-hosted with an on/offline vessel client; hosting and data-region details available on request. |
| Backups & continuity | Regular backups and reconciliation between ship and shore protect against data loss. |
Standards, Certifications & Assurance
We align our security programme to recognised maritime and information-security standards, including IMO MSC.428(98) cyber-risk guidance and ISM-aligned document control. For current certifications, attestations and audit evidence — or to run your own vendor security assessment — contact our team and we'll support your procurement due diligence.
Buying for a fleet? We welcome security questionnaires, penetration-test evidence requests and architecture reviews as a normal part of evaluation. Ask for our security pack when you book a demo.
Do your due diligence — we encourage it
Book a demo and bring your security team. We'll walk through access control, encrypted sync, audit trails and our cyber-risk alignment, and complete your vendor assessment.
Request a DemoFrequently Asked Questions
How does Volaxin secure ship-to-shore data?
Through encrypted synchronisation, role-based access, per-user authentication and full audit trails, with an offline-first design so data is neither exposed nor lost during connectivity outages.
Does Volaxin align with IMO cyber-risk requirements?
Yes — it's designed to support owners and managers meeting IMO MSC.428(98) and ISM cyber-risk obligations, but it complements rather than replaces your own SMS and policies.
Can we run a vendor security assessment?
Absolutely. We welcome security questionnaires, evidence requests and architecture reviews as part of procurement.