Security & Privacy

Sensitive maritime data deserves more than ordinary startup security.

The project is being designed around data minimisation, controlled access, source preservation and staged handling of sensitive matters.

Current design commitments

Data minimisation

Collect only what is needed for the relevant workflow and permission level.

Encryption

Production architecture is intended to encrypt data in transit and at rest with controlled key management.

Least privilege

Access should be role-based, purpose-limited and logged.

Originals preserved

AI extraction and translation never replace the original source file.

No data sale

Claimant, medical and family data are not a product for advertisers or sponsors.

No client-money custody

The platform is not designed to hold claimant settlement funds as a default operating model.

Controlled validation notice: do not send confidential, privileged or identifiable live case material unless a pilot agreement and data-processing instructions are in place.

AI data use

Identifiable client matter data should not be used to train general-purpose models without an explicit lawful, contractual and technical basis. Pilot vendors and data flows will be documented before live sensitive matter handling.

Detailed retention, deletion, access and incident-response controls will be supplied to pilot counterparties as the production pilot environment is finalised.