Aquadome

Legal

Legal

Security

Last updated: 26 May 2026

How we protect the platform and customer data. ISO/IEC 27001 guides the work. We are not certified.

Our approach

Aquadome BV builds software for maritime security and decision support. Protecting customer data is part of that work.

We organise security around ISO/IEC 27001 control areas. Those areas are risk assessment, access control, secure operations, supplier management, and continuous improvement. We add controls as the product changes.

We put product development first. A control is strict where the risk is high, and lighter where the exposure is low. We change that balance when a customer, a contract, or a regulation requires it.

Certification status

We have chosen not to pursue ISO 27001 certification yet. Product development comes first. We will look at certification again when a customer or a contract requires it.

When we say our practices are aligned with ISO 27001, we mean the standard guides how we work. An accredited body has not audited or certified our information security management system.

If procurement needs formal assurance, send your requirements early. We can then discuss questionnaires, architecture summaries, or specific controls.

Governance and risk

The founding team makes security decisions. We track assets, threats, and mitigations. Assets include the application, data stores, credentials, and infrastructure. We update those when we ship a major feature or change hosting.

  • Changes to production go through review and a controlled deployment.
  • Secrets and credentials are in environment configuration, not in source code.
  • We use a third-party service only when we need it, and we choose it with data location in mind.

Access control

Access to the application is by invitation. Sign-up is limited to approved email domains and pre-approved addresses. Administrative access is role-based.

  • Sessions are validated on the server.
  • Passwords must meet a minimum length. We ask people to use a strong, unique password.
  • Production databases and caches are not reachable from the public internet.
  • Operational tools, such as log viewers, require TLS and extra access controls.

We grant access only to people who need it, and we remove it when they no longer do.

Infrastructure and operations

The main systems run on infrastructure we operate in the European Union. Public endpoints use TLS. Core data services listen on localhost. Administrators reach them through an SSH tunnel. Database ports are not open on the internet.

  • A reverse proxy terminates TLS, HTTPS is automatic, and responses include security headers.
  • Services run in containers. That limits what is exposed on the host.
  • We back up data and test recovery periodically.
  • We keep logs for troubleshooting and incident review.

We update dependencies and base images as we develop. We patch a critical issue outside the normal release when it cannot wait.

Application and data handling

The marketing site and the application are separate. They use different routes and separate sessions. Personal data practices are described in our privacy policy.

  • Data in transit uses HTTPS and TLS.
  • The public site does not load advertising trackers or extra third-party scripts.
  • Marketing analytics use an EU-hosted provider and report in aggregate.
  • Contact email and transactional email go through providers set up for EU processing.

We process customer and operational data only for the purposes we describe to users and customers. We do not sell that data, and we do not use it for unrelated marketing.

Development and change

We ship often. Security checks run as part of that work.

  • Code is type-checked and linted. Automated checks run before merge.
  • We update dependencies and review known vulnerabilities during maintenance.
  • Application and infrastructure configuration defaults to least privilege.
  • Work on authentication, data export, or integrations gets extra review.

Formal change-advisory boards and long release gates stay light. The people who write a change own it, we keep each change small, and we can roll a release back quickly.

Suppliers and subprocessors

We use a small set of processors for hosting, email, analytics, and similar work. We choose them for security. Where data residency matters, we choose processors in the EU. The privacy policy lists the categories. Our contracts require processors to protect data and to use it only on our instructions.

Incidents and reporting

If you find a vulnerability, or you think someone accessed our services without permission, see our responsible disclosure policy or email hello@aquadome.ai. We investigate reports we consider credible, fix confirmed issues, and tell the people affected when the issue involves them.

We cannot promise that nothing will go wrong. When something does, we detect it, contain it, and record what we learned.

What may change

If we take on a larger deployment, a government customer, or a contract with a security schedule, we may tighten specific controls or seek ISO 27001 certification. We will update this page when these practices change.

Registered in Netherlands. Privacy rights and data categories are in Privacy. Rules for using the platform are in Terms of use.