SECURITY AND DATA

Crew data, protected the way it should be.

Pelastra processes sensitive data such as identity documents, medical information and wages. This page explains how that data is protected and who can access what.

Access control

Every screen and action is gated by a role permission, decided on the server.

Permission-based roles

Roles such as administrator, crew manager, technical manager, HSQE, procurement and accounting carry only the permissions their work needs.

Vessel-scoped access

A role can apply company-wide or only to selected vessels; records of out-of-scope vessels are not visible.

Segregation of duties

Rotation approval, above-threshold spend, invoice approval and wage approval are separate from preparation.

Enforced on the server

A hidden button is not a security measure; every unauthorised request is rejected by the server.

Data protection

Sensitive fields are shown only to those who need them, and files open through short-lived links.

Identity masking

Document numbers, email addresses and identity details are never sent to users without the right permission.

Short-lived file links

Documents and attachments open through signed links that expire within minutes; links cannot be stored and shared.

Encrypted offline store

Records waiting on board are encrypted on the device with a per-user key that cannot be exported.

Sanitised text

Free-text fields are stripped of HTML when saved; malicious content cannot be stored.

Traceability

Who changed what and when, and who viewed sensitive data, is on record.

Activity log

Changes to records are kept with who, when and which fields; administrators can review them.

Sensitive access log

Reads of data such as medical details, bank files and lists with document numbers are logged separately.

Traces instead of deletion

Wrong safety and vessel reports are not deleted; they are voided or amended with a reason.

Account and session security

Sessions are managed per device and closed on signs of misuse.

Per-device sessions

Users see their open sessions by device name and can sign out another device remotely.

Single-use refresh

A session refresh token is used once; if the same token is replayed, that device’s session chain is closed.

Rate limiting

Endpoints such as sign-in, password reset and messaging are limited by the number of attempts.

Privacy and data protection law

Personal data is processed under Turkish data protection law (KVKK), for clear purposes and with explicit consent where required.

Separate consent for health data

Medical information is a special category of data and is processed only with a separate consent that is unticked by default.

Consent-based sharing

Documents a seafarer entered themselves are opened to a company only if the seafarer accepts the invitation.

Anonymous reporting

For anonymous near-miss and hazard reports, the reporter’s identity is never stored on the server.

Time-limited share links

A seafarer’s profile share links expire and can be revoked; access is logged.

Have security questions?

Write to our team about hosting, backups, data processing agreements and your security assessment questionnaires.

Security and Data Protection | Pelastra