Shipmate / Security and privacy

Security and privacy

Shipmate is used by crews and shore organisations at operators who are themselves subject to strict documentation and compliance requirements. We see it as our job to make that part of the work simple for you.

On this page you will find how we handle data, which obligations we take on, and what documentation you receive as a customer. If you have a question this page does not answer, contact us at post@shipmate.no.

Where the data lives

All data in Shipmate is stored and processed within the EU/EEA. The application, database and authentication run on Amazon Web Services in Europe. Backups are stored within the EU/EEA.

One-time login codes are sent by SMS through Twilio, configured with data processing in Twilio's EU region. Delivery of the SMS itself then passes through mobile operator networks, which are outside both our control and Twilio's.

Beyond this, data does not leave the EU/EEA as part of normal operation, and we do not transfer customer data to third countries. The customer owns their own data. We do not use it for any purpose other than delivering the service, we do not sell it, and we do not use it to train AI models.

Login and access control

Login is passwordless. The user identifies themselves with their registered phone number and confirms with a one-time code sent to that same number. The phone number must be registered in advance by the company's administrator.

Access in Shipmate is role-based. Each user sees only what they are meant to see. The customer's administrator controls who has access to what, and access ends immediately when the company removes a user. All communication between user and service is encrypted. Data is encrypted at rest.

Our own access to customer data

We work on the principle of least privilege. Technical access to the production environment, cloud infrastructure and source code is restricted to a strictly limited set of named personnel and protected with two-factor authentication. In normal operation, this access is not used to read customer data.

When we assist with support or troubleshooting, the customer invites us into their own account, with the permissions the customer decides. That access can be withdrawn at any time.

Integration with your own systems

Shipmate synchronises crew and voyage data from your existing crewing and ISM systems. The synchronisation is one-way: we pull data into Shipmate, and only the fields needed to deliver the service. Your own system remains the source. We do not write data back to it.

What information we process

Shipmate processes personal data about crew and shore staff to the extent the company enters or synchronises it: name, position and contact details; vessel assignment and voyage plan; and messages the user sends or receives in the service.

Shipmate does not store health data.

Reliability and recovery

Uptime target 99.5 %. Backups daily. Backup retention 30 days. Customers are notified of planned maintenance that affects availability.

Security testing

Shipmate undergoes external security testing every six months. Findings are addressed according to severity. A summary of the most recent test can be shared with customers under a confidentiality agreement.

Incident handling

In the event of a security breach affecting personal data, we notify affected customers within 24 hours of the breach being discovered. The notification states what happened, which data is affected, what measures we have taken, and what the customer should do.

Sub-processors

Shipmate uses Amazon Web Services to run the application, database and authentication, and Twilio to send one-time codes by SMS. Both process data within the EU/EEA. A complete list is attached to the data processing agreement.

Privacy and data processing agreement

A data processing agreement is entered into with every customer as part of the contract. It describes the purpose of the processing, the categories of personal data, our technical and organisational measures, sub-processors and notification obligations.

Data export and deletion

Customers can request an export of their own data in a machine-readable format at any time. When the agreement ends, customer data is deleted from the production environment within 30 days. Deletion is confirmed in writing.

Framework and status

Shipmate's information security management system follows the structure of ISO/IEC 27001. We have started work towards certification with an external adviser. We are not certified today, and we think it is better to say so plainly than to use language that is not backed by anything.

Maritime context

Through IMO resolution MSC.428(98), shipping companies are required to address cyber risk in their safety management system. Customers receive a Cyber Security Statement describing what the system does, which data it processes, network dependencies and update routines.

Reporting vulnerabilities

If you have found a vulnerability in Shipmate, we would like to hear about it: post@shipmate.no. We confirm receipt within three working days and keep you informed until the case is closed.

Shipmate ASCompany registration number 935 208 246Responsible for information security: Emil Bonsaksen, CEOLast updated September 2026. Version 1.0.

Does your IT department have more questions?

Anthoni Giskegjerde, CTO, is happy to answer in writing ahead of a demo: ag@shipmate.no

Get in touch