Security
Last updated: 29.09.2026
Crewvector supports organisations managing seafarer records and documents. This page provides an overview of safeguards described for the platform.
Contractual scope
The services and binding security, confidentiality and data processing obligations applicable to a customer are governed by its signed Customer Agreement, validly agreed annexes and applicable law. This overview is not a separate service agreement, service-level agreement or data processing agreement. Its publication or revision does not amend a Customer Agreement or reduce mandatory legal obligations.
Hosting and encryption
The platform's application database and document storage are hosted in the European Economic Area. Supporting providers and relevant processing locations are described on our Sub-processors page.
Browser connections to the platform are protected using TLS. Backups are encrypted. Passwords are stored as one-way hashes rather than in readable form.
Customer access
Individual user credentials should not be shared. Customer organisations manage authorised users and the permissions available in their agreed configuration.
Data is logically separated between customer workspaces. Role-based permissions and access logging depend on the functionality and configuration supplied to the customer; contact us for the controls applicable to your deployment.
Crewvector access
Access to production systems is limited to authorised personnel with an operational need. Infrastructure administration may involve direct database access. Personnel access is limited to what is necessary to provide support, maintain the service and address security incidents under applicable instructions and confidentiality obligations.
Infrastructure provider control panels are protected by two-factor authentication.
Backups and operations
Backups, service monitoring and software maintenance support continuity and recovery. Backup schedules, recovery arrangements and any agreed service levels should be confirmed for the contracted service.
This page does not promise a particular uptime percentage, recovery time, recovery point or universal backup retention period.
Document extraction
Where enabled and used by a customer, automated document extraction involves the provider identified on the Sub-processors page. The extracted information is intended for review by an authorised user before it is relied on.
Incident handling
We investigate suspected security incidents and notify affected customers of personal data breaches without undue delay, in accordance with applicable law and the Customer Agreement. This page does not introduce a separate fixed notification deadline.
Customers acting as controllers assess their own obligations to authorities and affected individuals; Crewvector provides the assistance required by applicable law and binding arrangements.
Customer responsibilities
Customers should maintain current user access, remove access when personnel leave, protect credentials, assign appropriate permissions and establish lawful grounds for the information they supply.
These responsibilities do not replace Crewvector's own security and data protection obligations.
Data processing documentation
For information about the data processing terms applicable to your service, or to request documentation for contractual review, contact privacy@crewvector.com.
Our Privacy Policy explains the distinction between our own processing and processing on a customer's behalf.
Reporting security issues
Report suspected vulnerabilities to privacy@crewvector.com, including enough information to investigate. Do not include unnecessary personal data or credentials in a report.
Obtain written permission before conducting automated scans, load tests or penetration tests.
CREWVECTOR GLOBAL S.R.L.
36 Poporului Street, 1st Floor, Room 4, Constanța, Romania
Privacy and security: privacy@crewvector.com
General enquiries: info@crewvector.com