iVessel

Security & data protection

Security at iVessel

This page is written for the person who has to sign off on us — an owner's office, a management company, a government fleet. It says exactly what we do, where your data lives, who processes it, and what we do not claim. If you need a questionnaire completed or an architecture walkthrough, contact us.

What kind of data iVessel holds

iVessel holds operational vessel information: maintenance records and schedules, equipment and inventory lists, checklists, issues, documents you upload, and crew records including certificates and contact details. It does not hold payment card data (cards are entered directly with Stripe) and it is not designed for classified or financial information.

Certifications and infrastructure

All iVessel customer data is stored and processed within Supabase's infrastructure, which is SOC 2 Type II and HIPAA attested and runs on AWS. Physical, network and infrastructure controls — including AWS's IRAP assessment up to PROTECTED — are therefore inherited from those providers rather than assessed at iVessel directly.

IRAP and government engagements

IRAP assesses deployed systems rather than companies. We could scope an IRAP assessment of the deployed system if the engagement requires it; however, this cost would need to be factored into the engagement. For government customers we offer a dedicated deployment in an AWS region in their own country, so that vessel data, including backups, stays onshore.

Controls we operate

Multi-factor authentication

Authenticator-app (TOTP) MFA for every user; administrators can make it mandatory across their whole company. iVessel platform administrators are always required to use it.

Per-customer isolation

Every query is constrained by database row-level security to the company and boats the signed-in user belongs to.

Role-based access

Owner, captain, engineer, crew, contractor and warranty roles, with per-role page visibility and per-boat assignment.

Encryption

TLS 1.2+ in transit; AES-256 at rest for the database and file storage.

Backups and recovery

Daily automated backups retained for seven days, monthly restore verification, and a documented disaster-recovery plan.

No card data

Payments are processed by Stripe. iVessel never sees or stores full card numbers.

Account deletion

Users can delete their own account from inside the app; company administrators can remove users and boats.

Privacy framework

A GDPR-aligned framework: named processors, a lawful basis per purpose, consent-based analytics, and a data-subject-request process.

Where your data lives

Production data is hosted in AWS us-east-1 (United States) within Supabase. Backups are held in the same region. Organisations that need data to remain in a specific jurisdiction can be provisioned on a dedicated instance in another AWS region (for example Sydney for Australia); this is a separate deployment, set up at the start of the engagement.

Sub-processors

Primary processing happens entirely within Supabase on AWS. A small number of ancillary providers handle specific functions such as billing, email and barcode lookup. Our full sub-processor register, listing what each provider receives and where, is available on request — email info@ivessel.co.

Responsible disclosure

If you believe you have found a security issue, email info@ivessel.co with the details. We acknowledge reports within two business days and will not take action against good-faith research.

Need more?

We can complete your security questionnaire, walk your IT team through the architecture, or set up a dedicated regional deployment.

Contact us

We use cookies for analytics. iVessel LLC uses Google Analytics to understand how this site is used; in the EEA, UK and Switzerland nothing is set until you choose; you can change your choice any time from the footer. Cookie Policy