guest@sealogical:~
security

Security and data protection.

Sealogical holds crew passports, medical records, payroll and the safety record of every vessel on it. This page sets out how that data is protected — for the people who have to sign off on choosing us.

A full security and data protection overview for your review is available on request. Questions this page does not answer go to support@sealogical.com.

~ who can see what

Access.

Sign-in

Two steps, every time

Every sign-in asks for a one-time code emailed to the user as well as the password, unless that browser was trusted in the last 30 days. Repeated failed attempts lock the account for 15 minutes.

Permissions

Per section, per vessel

Access is granted per section — crew, safety, certificates, technical, vessel, charter, finance — on each vessel, so every user sees only what their role needs.

Sensitive data

Medical and payroll gated separately

Medical records and payroll each need their own permission, on top of general crew access, enforced both in the app and in the database.

~ where the data lives

Hosting and isolation.

Location

Held in the UK

The database, sign-in and file storage run on Supabase in London. The full list of providers and where each one runs is in our privacy notice.

Isolation

Separated in the database

Every table carries row-level security, so customers are separated in the database itself, not only in the app. Automated isolation tests check it on every change.

Encryption

In transit and at rest

AES-256 at rest, TLS 1.2+ in transit with HSTS. Documents sit in private storage and open only through short-lived signed links. Supabase and Vercel hold SOC 2 Type II and ISO 27001.

Backups

Point-in-time recovery

Point-in-time recovery backups are kept for 7 days. Data deleted from the platform expires from backups within that window.

AI features

Zero data retention

Document scanning and search send data to AI models through a gateway with zero data retention: the content is processed to answer the request and not kept or used for training.

Audit trail

Who did what, and when

An append-only audit log records sign-ins, permission changes, admin actions and data exports, kept for about 12 months. Your own account's records are available on request.

~ compliance

Certification and contracts.

Cyber Essentials

Certified

MXMG Ltd, which operates Sealogical, is Cyber Essentials certified for the whole organisation, valid to June 2027.

UK GDPR

Processor for your crew data

When you put crew and guest data into Sealogical, you are the controller and we are your processor. Clause 15 of our Terms is a data processing agreement under Article 28 UK GDPR, and a separate DPA can be signed on request.

Breach notification

Within 48 hours

If a personal data breach affects your data, we tell you without undue delay and within 48 hours, so you can meet your own 72-hour obligation.

Leaving

Your data, exported and deleted

On termination you get an export of your data in CSV, then deletion from production with written confirmation.

Registration

ICO registered

Sealogical is a trading name of MXMG Ltd, registered in the United Kingdom and with the Information Commissioner's Office (ZA932873).

~await contact_initiation

See it on your fleet.

A 30-minute walk-through with the team. No slides — the platform on your fleet's data.

Book a demo →