Our Security Principles

  • Least-privilege access. Role-based access control (RBAC) with per-user authentication means people see only the data and actions their role requires, across office and vessel.
  • Encrypted in transit. Ship-shore synchronisation and office access are designed to run over encrypted channels, so data is protected as it moves between vessel and shore.
  • Everything is auditable. Actions are logged with user, time and change detail, giving a defensible trail for internal audit, ISM and vetting.
  • Resilient by architecture. The vessel works fully offline and reconciles automatically — no reliance on a live link means no data loss and no exposure window during outages.
  • Controlled documents. The Document Management module distributes controlled, versioned SMS documents with read-receipts, reducing the risk of out-of-date procedures at sea.

Alignment with IMO Cyber-Risk & the ISM Code

Since 1 January 2021, IMO Resolution MSC.428(98) requires cyber risk to be addressed within a company's Safety Management System under the ISM Code. Volaxin is designed to support that obligation rather than complicate it:

  • Access control and authentication that map to your cyber-risk policy.
  • Audit logging that evidences "who did what, when" for DPA reviews and PSC.
  • Controlled SMS document distribution so cyber and safety procedures reach the vessel and are acknowledged.
  • Offline-first design that keeps critical operations running if connectivity is degraded or lost.
🛡️

Volaxin is a tool that supports your cyber-risk framework; it does not replace your own SMS, policies or crew training. We're happy to map our controls to your risk assessment during evaluation.

Data Handling & Privacy

We treat customer and crew data as a responsibility, not just an asset:

AreaApproach
Data ownershipYour operational data remains yours; we act as a processor for the purpose of delivering the service.
AccessRole-based, least-privilege, per-user — with administrative access restricted and logged.
Personal dataCrew and personal data handled with privacy-by-design principles and data-subject rights in mind.
Hosting & regionsCloud-hosted with an on/offline vessel client; hosting and data-region details available on request.
Backups & continuityRegular backups and reconciliation between ship and shore protect against data loss.

Standards, Certifications & Assurance

We align our security programme to recognised maritime and information-security standards, including IMO MSC.428(98) cyber-risk guidance and ISM-aligned document control. For current certifications, attestations and audit evidence — or to run your own vendor security assessment — contact our team and we'll support your procurement due diligence.

📋

Buying for a fleet? We welcome security questionnaires, penetration-test evidence requests and architecture reviews as a normal part of evaluation. Ask for our security pack when you book a demo.

Do your due diligence — we encourage it

Book a demo and bring your security team. We'll walk through access control, encrypted sync, audit trails and our cyber-risk alignment, and complete your vendor assessment.

Request a Demo

Frequently Asked Questions

How does Volaxin secure ship-to-shore data?

Through encrypted synchronisation, role-based access, per-user authentication and full audit trails, with an offline-first design so data is neither exposed nor lost during connectivity outages.

Does Volaxin align with IMO cyber-risk requirements?

Yes — it's designed to support owners and managers meeting IMO MSC.428(98) and ISM cyber-risk obligations, but it complements rather than replaces your own SMS and policies.

Can we run a vendor security assessment?

Absolutely. We welcome security questionnaires, evidence requests and architecture reviews as part of procurement.