SECURITY & COMPLIANCE

Protecting Your Data. Supporting Your Asset.

Tablet App

Running a yacht means handling sensitive information every day — crew contracts, guest details, financial transactions, and maintenance records. DeepBlue is designed to help keep that information protected, appropriately controlled, and traceable whenever you need to account for it.
Beyond data protection, DeepBlue is also designed to support the long-term management of the asset itself. Its Planned Maintenance System is supported by DNV Type Approval and Lloyd’s Register recognition, helping yacht operators maintain structured, traceable maintenance records aligned with recognised maritime standards and the expectations of surveyors, flag states, and insurers.
Compliance is therefore supported as part of day-to-day yacht operations, rather than reconstructed at the end of a season.

Access Control

You stay in control of who sees what

Access in DeepBlue is built around how yachts actually operate. Captains can be granted broader access than crew. DPAs and Managers can be given operational oversight, where appropriate. But no one should see more than their role requires, and users in the same position can be prevented from accessing each other’s sensitive personal data, depending on the permission structure configured by the System Administrator. Your System Administrator can adjust those boundaries in line with your operational and access control requirements.

security-overview
Fleet-wide overview

For fleet operators, the same customized permission structure can be applied across the entire fleet, so oversight is consistent without having to manage each yacht separately. 

Multi-Factor Authentication

Sensitive actions require proper sign-off

Not everything should be a one-click operation. Payment confirmations, changes to crew records, and edits to login credentials can be configured to require additional verification — either through multi-factor authentication on a mobile device, or a secondary PIN. This helps prevent mistakes or unauthorized actions from being completed without an additional control step.
Custom approval workflows mean you can also define who needs to authorize what before an action goes ahead — reflecting your internal approval structure and operational procedures.

2fa
MFA on Bank Processing
MFA on Bank Processing
MFA on Password Change
MFA on Password Change
MFA on Crew Data Change
MFA on Crew Data Change
MFA on Contract Authorization
MFA on Contract Authorization
Changelogs

Operational activity is traceable

Key user activity across the platform is logged with timestamp and user attribution. This includes data changes, approvals, access changes, authentication activity, financial confirmations, and maintenance completions.

security-changelog

Changelogs can be exported by authorised users when an auditor asks questions, a dispute arises, or you need to understand what happened and when.

Data Encryption

Your data is protected in transit and at rest

DeepBlue runs on professionally managed cloud infrastructure, with modern TLS encryption protecting data in transit and automated backup procedures supporting data resilience and recovery.

TLS encryption
ISO/IEC 27001

Your security is backed by an independently certified management system

DeepBlue is operated within an organisation that maintains ISO/IEC 27001 certification for its Information Security Management System (ISMS). This means that the organisation’s information security governance, risk management, infrastructure management, access control, and software deployment processes are independently assessed within the defined certification scope. ISO/IEC 27001 certifies the management system, not the DeepBlue software product as a standalone product.

ISO/IEC
GDPR Compliance

Personal data stays under your control

The platform is designed to support GDPR compliance, with your System Administrator controlling role-based access to personal data across the platform in line with configured permissions and internal access control requirements.

gdpr
Certified Maintenance System

Your PMS records are built for audit review

For planned maintenance, DeepBlue’s Planned Maintenance System is supported by DNV Type Approval and Lloyd’s Register Software Conformity Assessment, within the applicable approval and assessment scope.
In practical terms, this means that when a surveyor or auditor reviews maintenance compliance, they can review structured, traceable maintenance records in the same operational system used by the crew day to day — reducing reliance on separate paper records or documentation assembled after the fact.

( CERTIFIED )
Lloyd’s Register Software Conformity Assessment
Lloyd’s Register Software Conformity Assessment

DeepBlue holds Lloyd’s Register Software Conformity Assessment, confirming our PMS meets the technical and operational requirements of LR’s software certification framework.

DNV Type Approval
DNV Approved Product

DeepBlue’s Planned Maintenance System has received DNV Type Approval — independently verified to meet classification society standards for maintenance management software.