Shipmate / Security and privacy
Security and privacy
Shipmate is used by crews and shore organisations at operators who are themselves subject to strict documentation and compliance requirements. We see it as our job to make that part of the work simple for you.
On this page you will find how we handle data, which obligations we take on, and what documentation you receive as a customer. If you have a question this page does not answer, contact us at post@shipmate.no.
Where the data lives
All data in Shipmate is stored and processed within the EU/EEA. The application, database and authentication run on Amazon Web Services in Europe. Backups are stored within the EU/EEA.
One-time login codes are sent by SMS through Twilio, configured with data processing in Twilio's EU region. Delivery of the SMS itself then passes through mobile operator networks, which are outside both our control and Twilio's.
Beyond this, data does not leave the EU/EEA as part of normal operation, and we do not transfer customer data to third countries. The customer owns their own data. We do not use it for any purpose other than delivering the service, we do not sell it, and we do not use it to train AI models.
Login and access control
Login is passwordless. The user identifies themselves with their registered phone number and confirms with a one-time code sent to that same number. The phone number must be registered in advance by the company's administrator.
Access in Shipmate is role-based. Each user sees only what they are meant to see. The customer's administrator controls who has access to what, and access ends immediately when the company removes a user. All communication between user and service is encrypted. Data is encrypted at rest.
Our own access to customer data
We work on the principle of least privilege. Technical access to the production environment, cloud infrastructure and source code is restricted to a strictly limited set of named personnel and protected with two-factor authentication. In normal operation, this access is not used to read customer data.
When we assist with support or troubleshooting, the customer invites us into their own account, with the permissions the customer decides. That access can be withdrawn at any time.
Integration with your own systems
Shipmate synchronises crew and voyage data from your existing crewing and ISM systems. The synchronisation is one-way: we pull data into Shipmate, and only the fields needed to deliver the service. Your own system remains the source. We do not write data back to it.
What information we process
Shipmate processes personal data about crew and shore staff to the extent the company enters or synchronises it: name, position and contact details; vessel assignment and voyage plan; and messages the user sends or receives in the service.
Shipmate does not store health data.
Reliability and recovery
Uptime target 99.5 %. Backups daily. Backup retention 30 days. Customers are notified of planned maintenance that affects availability.
Security testing
Shipmate undergoes external security testing every six months. Findings are addressed according to severity. A summary of the most recent test can be shared with customers under a confidentiality agreement.
Incident handling
In the event of a security breach affecting personal data, we notify affected customers within 24 hours of the breach being discovered. The notification states what happened, which data is affected, what measures we have taken, and what the customer should do.
Sub-processors
Shipmate uses Amazon Web Services to run the application, database and authentication, and Twilio to send one-time codes by SMS. Both process data within the EU/EEA. A complete list is attached to the data processing agreement.
Privacy and data processing agreement
A data processing agreement is entered into with every customer as part of the contract. It describes the purpose of the processing, the categories of personal data, our technical and organisational measures, sub-processors and notification obligations.
Data export and deletion
Customers can request an export of their own data in a machine-readable format at any time. When the agreement ends, customer data is deleted from the production environment within 30 days. Deletion is confirmed in writing.
Framework and status
Shipmate's information security management system follows the structure of ISO/IEC 27001. We have started work towards certification with an external adviser. We are not certified today, and we think it is better to say so plainly than to use language that is not backed by anything.
Maritime context
Through IMO resolution MSC.428(98), shipping companies are required to address cyber risk in their safety management system. Customers receive a Cyber Security Statement describing what the system does, which data it processes, network dependencies and update routines.
Reporting vulnerabilities
If you have found a vulnerability in Shipmate, we would like to hear about it: post@shipmate.no. We confirm receipt within three working days and keep you informed until the case is closed.
Does your IT department have more questions?
Anthoni Giskegjerde, CTO, is happy to answer in writing ahead of a demo: ag@shipmate.no