
SECURITY AND DATA
Crew data, protected the way it should be.
Pelastra processes sensitive data such as identity documents, medical information and wages. This page explains how that data is protected and who can access what.
Access control
Every screen and action is gated by a role permission, decided on the server.
Permission-based roles
Roles such as administrator, crew manager, technical manager, HSQE, procurement and accounting carry only the permissions their work needs.
Vessel-scoped access
A role can apply company-wide or only to selected vessels; records of out-of-scope vessels are not visible.
Segregation of duties
Rotation approval, above-threshold spend, invoice approval and wage approval are separate from preparation.
Enforced on the server
A hidden button is not a security measure; every unauthorised request is rejected by the server.
Data protection
Sensitive fields are shown only to those who need them, and files open through short-lived links.
Identity masking
Document numbers, email addresses and identity details are never sent to users without the right permission.
Short-lived file links
Documents and attachments open through signed links that expire within minutes; links cannot be stored and shared.
Encrypted offline store
Records waiting on board are encrypted on the device with a per-user key that cannot be exported.
Sanitised text
Free-text fields are stripped of HTML when saved; malicious content cannot be stored.
Traceability
Who changed what and when, and who viewed sensitive data, is on record.
Activity log
Changes to records are kept with who, when and which fields; administrators can review them.
Sensitive access log
Reads of data such as medical details, bank files and lists with document numbers are logged separately.
Traces instead of deletion
Wrong safety and vessel reports are not deleted; they are voided or amended with a reason.
Account and session security
Sessions are managed per device and closed on signs of misuse.
Per-device sessions
Users see their open sessions by device name and can sign out another device remotely.
Single-use refresh
A session refresh token is used once; if the same token is replayed, that device’s session chain is closed.
Rate limiting
Endpoints such as sign-in, password reset and messaging are limited by the number of attempts.
Privacy and data protection law
Personal data is processed under Turkish data protection law (KVKK), for clear purposes and with explicit consent where required.
Separate consent for health data
Medical information is a special category of data and is processed only with a separate consent that is unticked by default.
Consent-based sharing
Documents a seafarer entered themselves are opened to a company only if the seafarer accepts the invitation.
Anonymous reporting
For anonymous near-miss and hazard reports, the reporter’s identity is never stored on the server.
Time-limited share links
A seafarer’s profile share links expire and can be revoked; access is logged.
Have security questions?
Write to our team about hosting, backups, data processing agreements and your security assessment questionnaires.