Security that withstands owner scrutiny.
HelmOps is built for high-stakes yachting operations where trust is absolute. Financials, crew data, and operational records are protected with encryption, tenant isolation, and access controls aligned to industry standards.
Least-privilege access
Role-based permissions keep owner financials and operational data visible only to the right roles and approvals.
Encryption by default
Data is encrypted in transit and at rest, with tenant isolation across yacht and fleet accounts.
Audit trail visibility
Audit trails are supported for expenses and approvals to maintain defensible operational records.
Offline-tolerant resilience
Entries are captured in an on-device outbox and sync securely once connectivity returns.
Defense in depth
Security is engineered in layers, not slogans.
Yachts operate with shifting crews, vendors, and schedules. Each workflow is validated and recorded so owners and captains can answer questions with confidence.
Device & onboard
Secure sessions and offline safeguards protect bridge and crew workflows when connectivity is limited.
Application
Granular permissions and approvals protect expense, crew, and voyage workflows.
Data
Tenant isolation and encrypted storage protect operational data.
Infrastructure
Access controls and monitoring align with industry standards for resilient operations.
Operational assurance
Evidence you can show an owner.
Audit trails and approval records provide defensible answers when owners need proof.
Expense approvals mapped to owner policies
Crew actions can be logged with time and role context
Vendor payments can require explicit approvals
Encryption in transit and at rest
Operational data is encrypted during transfer and while stored.
Tenant isolation
Each yacht's data is isolated per tenant to prevent cross-vessel exposure.
No advertising use
Customer data is not used for advertising; commitments are defined in the Privacy Charter.
Certification status
What we hold, and what we do not.
HelmOps does not currently hold ISO/IEC 27001 certification, DNV Type Approval, or a Lloyd's Register Software Conformity Assessment. We would rather state that plainly than imply otherwise. Below is what is verifiable today: how data is handled, who processes it, and what an independent reviewer can check. If your flag state, class society, or management company requires type-approved software, evaluate that requirement first.
What software certification actually covers →Security review
We review our own security, and we say when.
An internal security review of the platform was completed on 20 May 2026, covering authentication, API surface, file handling, mobile sync, the service worker, and the admin panel. It produced 26 findings across all severities. Both critical findings were remediated, along with the majority of high-severity findings. Remaining items are documented in an internal findings register with severity, status, and the reasoning behind each deferral.
This was an internal review, not an independent third-party penetration test. We do not describe it as one. Specific unremediated findings are not published, since doing so would expose customers to the very risk the review exists to reduce. Security researchers can reach us through the contact channel below for coordinated disclosure.
Subprocessors
Who else touches your data.
Operational data is processed by the infrastructure providers below. Their certifications are theirs, not ours — we list them so due diligence has a starting point rather than a dead end.
| Provider | What it processes |
|---|---|
| Vercel | Application hosting, edge delivery, and request routing. |
| Supabase | Primary database and file storage for operational records. |
| Stripe | Subscription billing. Card details are handled by Stripe, never stored by HelmOps. |
| Sentry | Application error monitoring and diagnostics. |
| Upstash | Rate limiting and ephemeral operational caching. |
| Cloudflare | Bot protection on sign-up and verification flows. |
| OpenAI | Voice transcription and task extraction for AI-assisted entry. |
| Apple | iOS application distribution and push delivery. |
Global readiness
Built for world-class yachting corridors.
Owners, captains, and fleet offices operate across jurisdictions. HelmOps supports consistent policies without sacrificing speed or clarity.
Key hubs
Owner confidentiality
Sensitive spend, itinerary, and staffing data stays tightly controlled with explicit approvals.
Captain-grade accountability
Operational decisions are logged for transparency and safety with clear responsibility trails.
Fleet office clarity
Multi-yacht oversight with segmentation and reporting boundaries for executive-ready insight.
Security FAQ