Security & Compliance

ISO 27001 certified, DNV approved, EU-hosted, and trusted by fleet operators and government maritime authorities.

Compliance

ISO/IEC 27001:2022

LRQA (Lloyd's Register)

DNV Type Approval

Det Norske Veritas (DNV)

GDPR Compliant

EU Regulation 2016/679

EU Data Residency

Marad Policy

Controls

View all
Infrastructure Security
7 controls
  • EU-only infrastructure in certified datacentres
  • Automated daily encrypted backups with 30-day retention
  • DDoS mitigation and intrusion detection active
View 4 more Infrastructure Security controls
Organisational Security
6 controls
  • ISO/IEC 27001:2022 certified (LRQA)
  • Annual third-party penetration testing
  • Security awareness training for all staff
View 3 more Organisational Security controls
Access & Identity
7 controls
  • Multi-factor authentication (MFA) enforced
  • Role-based access control (RBAC)
  • Single sign-on (SSO) via OIDC
View 4 more Access & Identity controls
Data Protection
7 controls
  • AES-256 encryption at rest
  • TLS 1.2+ encryption in transit
  • Strict multi-tenant data isolation
View 4 more Data Protection controls
Secure Development
7 controls
  • Automated static code analysis and dependency scanning on every commit
  • Mandatory four-eyes peer review before any code is merged
  • Automated security gate blocks merges on critical vulnerabilities
View 4 more Secure Development controls

Security Controls

Comprehensive coverage across infrastructure, access, and data protection

Updated June 2025

Infrastructure Security

7 controls
Active
  • EU-only infrastructure in certified datacentres
  • Automated daily encrypted backups with 30-day retention
  • DDoS mitigation and intrusion detection active
  • High availability with automatic failover
  • 99.9% uptime SLA
  • Vulnerability scanning and patch management
  • Network segregation and firewall rules enforced

Organisational Security

6 controls
Active
  • ISO/IEC 27001:2022 certified (LRQA)
  • Annual third-party penetration testing
  • Security awareness training for all staff
  • Incident response procedure documented and tested
  • Supplier and vendor security assessments
  • Security policy reviewed and approved annually

Access & Identity

7 controls
Active
  • Multi-factor authentication (MFA) enforced for all users
  • Role-based access control (RBAC)
  • Single sign-on (SSO) via OIDC
  • Configurable session timeouts
  • Concurrent session limits
  • Privileged access management and reviews
  • Access reviews conducted quarterly

Data Protection

7 controls
Active
  • AES-256 encryption at rest
  • TLS 1.2+ encryption in transit with HSTS enforced
  • Strict multi-tenant data isolation
  • GDPR-compliant data processing agreements
  • EU-only data residency guaranteed
  • Data retention policies enforced
  • Right to erasure and portability supported

Secure Development

7 controls
Active
  • Automated static code analysis and dependency scanning on every commit
  • Mandatory four-eyes peer review before any code is merged
  • Automated security gate blocks merges on critical vulnerabilities
  • Separate development, staging, and production environments
  • Automated daily builds and test runs
  • Version-controlled infrastructure and deployment pipelines
  • Regular application-level penetration testing

Resources

Certificates and documents available on request

ISO 27001 Certificate

LRQA-issued certificate (valid until Oct 2028)

Request copy

DNV Type Approval

Det Norske Veritas PMS type approval certificate

Request copy

Statement of Applicability

ISO 27001 controls applicability statement (SOA)

Request access

Penetration Test Summary

Annual third-party pen test executive summary

Request under NDA

Data Processing Agreement

GDPR-compliant DPA for enterprise customers

Request DPA

Privacy Policy

How we collect, use, and protect your data

View policy

Frequently Asked Questions

Common questions about Marad's security and compliance

Have a security question?

Our security and compliance team is available to answer questions from customers, auditors, and procurement teams. We aim to respond within one business day.

CISO

Johannes van Urk

security@marad.com
DPO

Jacob Hakvoort

dpo@marad.com