Security Policy

LogicDock Maritime Management System

Last Updated: July 23, 2026

1. OVERVIEW

LogicDock Maritime Management System ("LogicDock") is committed to protecting the security of customer data and maintaining the trust of our users. This Security Policy describes the administrative, technical, and physical safeguards we have implemented to protect customer information.

2. DATA ENCRYPTION

In Transit: All data transmitted between users and LogicDock servers is encrypted using TLS 1.2 or higher with industry-standard cipher suites.
At Rest: Customer databases are hosted on encrypted storage volumes. Database credentials are protected using industry-standard encoding and access controls.
Payment Data: LogicDock does not store credit card numbers, CVV codes, or other sensitive payment instrument details. All payment processing is handled by Square, Inc., a PCI-DSS Level 1 compliant payment processor. LogicDock stores only tokenized card references (card-on-file IDs) provided by Square.

3. ACCESS CONTROLS

3.1 Authentication

All administrative and user access requires authenticated credentials. Passwords are stored using bcrypt hashing. Session management includes automatic timeout after periods of inactivity.

3.2 Role-Based Access

LogicDock enforces role-based access control (RBAC). Users are assigned roles (admin, owner, user) that determine their permissions within the system. IT-support administrative access is segregated from customer data access.

3.3 IT-Support Access

IT-support administrators have access to system management functions but do not have direct access to customer operational data without explicit authorization. All administrative actions are logged in an audit trail.

4. INFRASTRUCTURE SECURITY

4.1 Hosting

LogicDock is hosted on dedicated server infrastructure with firewall protection, regular security updates, and intrusion detection monitoring.

4.2 Database Isolation

Each customer company receives an isolated database instance. Cross-company data access is prevented at the database level through separate credentials and access controls.

4.3 Backups

Database backups are performed on a regular schedule and stored in encrypted form. Backup retention follows a rolling schedule with secure deletion of expired backups.

5. VULNERABILITY MANAGEMENT

5.1 Patch Management

LogicDock applies security patches to server infrastructure, dependencies, and application code on a regular basis. Critical security patches are applied within 48 hours of release.

5.2 Dependency Scanning

Third-party dependencies are monitored for known vulnerabilities. Vulnerable packages are updated or replaced as needed.

5.3 Code Reviews

Application code changes undergo review before deployment. Security-sensitive areas (authentication, payments, data access) require additional review.

6. INCIDENT RESPONSE

6.1 Detection

LogicDock monitors system logs, access patterns, and error rates for signs of security incidents. Automated alerts are generated for suspicious activity.

6.2 Notification

In the event of a confirmed security breach affecting customer data, LogicDock will notify affected customers within 72 hours of confirmation. Notifications will include the nature of the breach, data affected, and remediation steps taken.

6.3 Remediation

Upon discovering a security incident, LogicDock will take immediate steps to contain the incident, investigate the scope, implement fixes, and prevent recurrence.

7. DATA RETENTION & DISPOSAL

Customer data is retained in accordance with our Terms of Service. Upon termination, customer data is securely deleted from active systems within 30-60 days. Backup copies are overwritten on a rolling 90-day schedule. See the Terms of Service for full details on data retention.

8. COMPLIANCE

LogicDock aligns its security practices with industry frameworks including NIST Cybersecurity guidelines. Payment processing complies with PCI-DSS requirements through our partnership with Square, Inc.

9. SECURITY CONTACT

For security-related questions, vulnerability reports, or incident notifications, contact: security@logicdock.org

We acknowledge security reports within 48 hours and provide regular updates on remediation progress.

Back to Homepage