Free tool
Ship-to-shore data security & ownership checklist
Before any maritime software touches your vessels' data, someone should ask these 29 questions. They are organised around the decisions that are expensive to reverse: who owns the data, where it sits, what reaches the ship's networks, and what the vendor's certificates actually cover. Tick as you review — nothing you mark is sent or stored anywhere, and it resets when you leave the page.
Data ownership & exit
The question that decides every other question: whose data is it, and can you leave with it?
Hosting & jurisdiction
Where the data sits decides which laws and which authorities reach it.
Access control
Most maritime data incidents are access incidents, not exotic attacks.
Onboard OT/IT separation
IACS UR E26/E27 made cyber resilience a class matter for newbuilds — the logic applies to any fleet.
Ship–shore link
The link is the exposed surface: satellite terminals, routers, shared crew bandwidth.
AI-specific questions
AI features change the data question: what leaves your tenant, and what does the model remember?
Vendor verification
A certificate is a claim about a scope — read the scope, not the logo.
This is a due-diligence aid built on publicly available frameworks — IMO's guidelines on maritime cyber risk management (MSC-FAL.1/Circ.3) and IACS UR E26/E27. It is not legal advice, and it does not replace review by your lawyer or classification society.
Questions
Is a vendor's ISO 27001 certificate enough on its own?
No. ISO 27001 certifies a management system within a defined scope. The scope statement may cover a different legal entity, a different product, or only the head office. Ask for the certificate's scope wording and check that it names the entity and the service you are actually buying.
Does this checklist replace a legal or class review?
No. It is a structured due-diligence question set for owners and managers evaluating maritime software and data services — a way to find the weak answers before signing. Contract wording belongs with your lawyer; class implications of onboard installations belong with your classification society.
Why so much emphasis on exit and data return?
Because the moment you need it is the moment you have least leverage. A vendor relationship that cannot be exited with your data intact is not a service — it is a dependency. Exit terms are cheapest to fix before signature and nearly impossible after.
Keep this result working for you
Leave your email for the preparation checklist and the regulatory developments that move dates like these — no spam, only what matters.
Get it by emailStay Ahead of Important Maritime Developments
Leave your email to receive selected maritime developments and updates from Apeks Tech. No spam — only what matters.