Security posture

How the platform is built and operated.

A summary of the controls behind Navis Arca. Detailed documentation — architecture, control matrices, penetration-test summaries — is available to customers and active prospects under NDA.

Encryption in transit

All traffic between the vessel agent, the operator console and the cloud control plane is encrypted with TLS. Stored data is encrypted at rest.

MFA & role-based access

Operator access to a tenant requires multi-factor authentication and is governed by role-based access control, with a queryable, tamper-evident audit log of every action.

Tenancy & data residency

The control plane is multi-tenant and region-pinned, so customer data stays in the region you choose. Tenants are logically isolated from one another.

Least-privilege support

Any Navis Arca or Necurity access to your tenant is time-limited, fully audited, and initiated by you from the console. No standing access to customer data.

Monitoring & testing

The platform is subject to internal Red Team / VAPT cycles using the same methodology Necurity applies to enterprise customers, with continuous vulnerability management.

ISO 27001 ISMS

Navis Arca is built and operated by Necurity Solutions, which maintains an independently audited ISO/IEC 27001-certified information security management system.

Documents & policies

Everything a vendor review needs.

Self-serve the standard documents below. Anything not published here — SOC-style control summaries, architecture diagrams, penetration-test letters, questionnaire responses (CAIQ / SIG) — is available under NDA on request.

Running a vendor security review?

We'll send our security package — control summaries, architecture overview, test letters and a completed questionnaire — under NDA, and join a call with your security team.

Request our security package →