Security and data protection.
Sealogical holds crew passports, medical records, payroll and the safety record of every vessel on it. This page sets out how that data is protected — for the people who have to sign off on choosing us.
A full security and data protection overview for your review is available on request. Questions this page does not answer go to support@sealogical.com.
~ who can see what
Access.
Sign-in
Two steps, every time
Every sign-in asks for a one-time code emailed to the user as well as the password, unless that browser was trusted in the last 30 days. Repeated failed attempts lock the account for 15 minutes.
Permissions
Per section, per vessel
Access is granted per section — crew, safety, certificates, technical, vessel, charter, finance — on each vessel, so every user sees only what their role needs.
Sensitive data
Medical and payroll gated separately
Medical records and payroll each need their own permission, on top of general crew access, enforced both in the app and in the database.
~ where the data lives
Hosting and isolation.
Location
Held in the UK
The database, sign-in and file storage run on Supabase in London. The full list of providers and where each one runs is in our privacy notice.
Isolation
Separated in the database
Every table carries row-level security, so customers are separated in the database itself, not only in the app. Automated isolation tests check it on every change.
Encryption
In transit and at rest
AES-256 at rest, TLS 1.2+ in transit with HSTS. Documents sit in private storage and open only through short-lived signed links. Supabase and Vercel hold SOC 2 Type II and ISO 27001.
Backups
Point-in-time recovery
Point-in-time recovery backups are kept for 7 days. Data deleted from the platform expires from backups within that window.
AI features
Zero data retention
Document scanning and search send data to AI models through a gateway with zero data retention: the content is processed to answer the request and not kept or used for training.
Audit trail
Who did what, and when
An append-only audit log records sign-ins, permission changes, admin actions and data exports, kept for about 12 months. Your own account's records are available on request.
~ compliance
Certification and contracts.
Cyber Essentials
Certified
MXMG Ltd, which operates Sealogical, is Cyber Essentials certified for the whole organisation, valid to June 2027.
UK GDPR
Processor for your crew data
When you put crew and guest data into Sealogical, you are the controller and we are your processor. Clause 15 of our Terms is a data processing agreement under Article 28 UK GDPR, and a separate DPA can be signed on request.
Breach notification
Within 48 hours
If a personal data breach affects your data, we tell you without undue delay and within 48 hours, so you can meet your own 72-hour obligation.
Leaving
Your data, exported and deleted
On termination you get an export of your data in CSV, then deletion from production with written confirmation.
Registration
ICO registered
Sealogical is a trading name of MXMG Ltd, registered in the United Kingdom and with the Information Commissioner's Office (ZA932873).
~await contact_initiation
See it on your fleet.
A 30-minute walk-through with the team. No slides — the platform on your fleet's data.
Book a demo →