Security you can verify.
A crew career lives in sensitive documents, IDs, ENG1 medicals, certifications and sea-service records. YWC treats that special-category data with the protection it deserves: encrypted, access-controlled, and handled under GDPR.
How we protect your data
Security built around special-category data.
Crew documents are some of the most sensitive data anyone carries, government IDs, medical fitness certificates and certifications. These are the controls that protect them. [placeholder: all specifics below must be confirmed by engineering before launch]
Encryption in transit & at rest
All traffic is served over TLS (1.2+). Documents and data at rest are encrypted with AES-256. [placeholder: confirm versions]
In placeAccess control & least privilege
Role-based access, least-privilege defaults and audited admin access. Crew control who can view their documents. [placeholder: confirm]
In placeSecure document handling & verification
Uploads, OCR and credential verification are handled through Crewdentials with isolated, encrypted storage.
In placeInfrastructure & hosting
Hosted with a reputable cloud provider in [placeholder: region], with network isolation and hardened configuration. [placeholder: confirm provider/region]
In placeMonitoring & logging
Centralised application and access logging with alerting on anomalous activity. [placeholder: confirm tooling]
In placeBackups & disaster recovery
Encrypted, regular backups with a documented recovery plan and tested restores. [placeholder: confirm RPO/RTO & cadence]
In placeData protection & privacy
GDPR by design, for the data that matters most.
Yacht Workers Council ("YWC") is the GDPR Data Controller for crew personal data on the registry. Registered office: 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF.
Special-category data & lawful basis
Some crew data, including ID documents, medical fitness certificates (e.g. ENG1) and certifications, constitutes special-category data under Article 9 of the UK GDPR / EU GDPR. We process it on the lawful basis of Article 9(2)(b) (rights and obligations in the field of employment), alongside Article 6 lawful bases for general processing. [placeholder: confirm full lawful-basis mapping with DPO/legal]
Data residency & retention
Crew data is stored in [placeholder: region, EU/UK]. We retain personal data only as long as needed to provide the service and meet legal obligations, after which it is deleted or anonymised. Full retention periods are set out in our Privacy Policy. [placeholder: confirm residency & retention]
Sub-processors
We use a small set of vetted sub-processors to deliver the registry, including Crewdentials (document storage, OCR and verification), DSS (Digital Sea Service) and Anjin (background verification). Each is bound by a data-processing agreement. The current list and details are in our Data Processing Agreement.
Your rights
Crew can access, correct, export and delete their data. To exercise your rights, see the Privacy Policy or contact us.
Application security
Secure from code to account.
Secure development lifecycle
Changes go through peer code review and automated checks before release. Security is considered at design and review stages, not bolted on afterwards. [placeholder: confirm SDLC details]
Dependency & vulnerability scanning
We scan dependencies for known vulnerabilities and patch on a prioritised basis. [placeholder: confirm tooling & SLA]
Penetration testing
We commission independent penetration testing on a [placeholder: cadence, e.g. annual] basis and remediate findings by severity. [placeholder: confirm cadence & provider]
Account & session security
- Multi-factor authentication (MFA / 2FA) available on accounts. [placeholder: confirm enforcement]
- Passwords stored using strong, salted hashing. [placeholder: confirm algorithm]
- Session security with secure, HTTP-only cookies and sensible expiry.
- Crew control document visibility, private until shared.
Compliance & certifications
Where we are, stated honestly.
We will only claim a certification once it is held and current. Today our posture is GDPR-aligned; formal certifications are on the roadmap.
Responsible disclosure
Found a vulnerability? Tell us.
We welcome reports from security researchers and treat them as a partnership, not a threat. If you believe you have found a security issue in YWC, please tell us before disclosing it publicly.
Email security teamHow to report: email [email protected] [placeholder: confirm address] with steps to reproduce, affected URLs and any proof-of-concept. A machine-readable contact is also published at /.well-known/security.txt.
Response SLA: we aim to acknowledge reports within [placeholder: e.g. 3 business days] and to keep you updated through remediation.
Scope
- In scope: the YWC web application and APIs under
yachtworld.communityand YWC-operated services. [placeholder: confirm scope] - Out of scope: third-party services (e.g. partner platforms), volumetric/DoS testing, social engineering and physical attacks.
Safe harbour
If you make a good-faith effort to comply with this policy, act only against in-scope targets, avoid privacy violations and data destruction, and give us reasonable time to remediate before public disclosure, we will not pursue legal action against you. [placeholder: confirm safe-harbour wording with legal]
Sub-processors & partners
Specialists handle the most sensitive parts.
We integrate rather than reinvent. The most sensitive processing is delegated to vetted partners, each under a data-processing agreement. Full details are in the DPA.
Document storage, OCR & verification
Encrypted storage and credential verification for every document on the registry.
How verification worksDigital Sea Service
Sea time and STCW rest hours processed into an auditable, shareable record.
About Digital Sea ServiceBackground verification
Advanced background checks for safer hiring, available as an add-on.anjin.info
About background checksSecurity questions
Common security questions.
Can't find what you're looking for? Reach out and we'll get back to you.
Contact usHow is my data encrypted?
All traffic to YWC is served over TLS (1.2 or higher), and data, including your documents, is encrypted at rest with AES-256. [placeholder: confirm exact versions]
How do you handle my ID and ENG1 medical?
These are treated as special-category data under GDPR Article 9. They are stored encrypted, access is restricted on a least-privilege basis, and document handling and verification run through our partner Crewdentials. You control who can view them, documents are private until you choose to share.
Are you ISO 27001 or SOC 2 certified?
Not yet. We are GDPR-aligned today and we will not claim a certification we do not hold. ISO/IEC 27001 and SOC 2 are on our roadmap. [placeholder: in progress / roadmap]
Where is my data stored?
Crew data is hosted in [placeholder: region, EU/UK] with a reputable cloud provider. Data residency and retention details are set out in our Privacy Policy and DPA.
How do I report a security issue?
Email [email protected] [placeholder: confirm address] or see our responsible disclosure policy above. We act in good faith with researchers and offer a safe-harbour commitment.