Sensitive maritime data deserves more than ordinary startup security.
The project is being designed around data minimisation, controlled access, source preservation and staged handling of sensitive matters.
Current design commitments
Data minimisation
Collect only what is needed for the relevant workflow and permission level.
Encryption
Production architecture is intended to encrypt data in transit and at rest with controlled key management.
Least privilege
Access should be role-based, purpose-limited and logged.
Originals preserved
AI extraction and translation never replace the original source file.
No data sale
Claimant, medical and family data are not a product for advertisers or sponsors.
No client-money custody
The platform is not designed to hold claimant settlement funds as a default operating model.
AI data use
Identifiable client matter data should not be used to train general-purpose models without an explicit lawful, contractual and technical basis. Pilot vendors and data flows will be documented before live sensitive matter handling.
Detailed retention, deletion, access and incident-response controls will be supplied to pilot counterparties as the production pilot environment is finalised.