LogicDock Maritime Management System
All administrative and user access requires authenticated credentials. Passwords are stored using bcrypt hashing. Session management includes automatic timeout after periods of inactivity.
LogicDock enforces role-based access control (RBAC). Users are assigned roles (admin, owner, user) that determine their permissions within the system. IT-support administrative access is segregated from customer data access.
IT-support administrators have access to system management functions but do not have direct access to customer operational data without explicit authorization. All administrative actions are logged in an audit trail.
LogicDock is hosted on dedicated server infrastructure with firewall protection, regular security updates, and intrusion detection monitoring.
Each customer company receives an isolated database instance. Cross-company data access is prevented at the database level through separate credentials and access controls.
Database backups are performed on a regular schedule and stored in encrypted form. Backup retention follows a rolling schedule with secure deletion of expired backups.
LogicDock applies security patches to server infrastructure, dependencies, and application code on a regular basis. Critical security patches are applied within 48 hours of release.
Third-party dependencies are monitored for known vulnerabilities. Vulnerable packages are updated or replaced as needed.
Application code changes undergo review before deployment. Security-sensitive areas (authentication, payments, data access) require additional review.
LogicDock monitors system logs, access patterns, and error rates for signs of security incidents. Automated alerts are generated for suspicious activity.
In the event of a confirmed security breach affecting customer data, LogicDock will notify affected customers within 72 hours of confirmation. Notifications will include the nature of the breach, data affected, and remediation steps taken.
Upon discovering a security incident, LogicDock will take immediate steps to contain the incident, investigate the scope, implement fixes, and prevent recurrence.
Customer data is retained in accordance with our Terms of Service. Upon termination, customer data is securely deleted from active systems within 30-60 days. Backup copies are overwritten on a rolling 90-day schedule. See the Terms of Service for full details on data retention.
LogicDock aligns its security practices with industry frameworks including NIST Cybersecurity guidelines. Payment processing complies with PCI-DSS requirements through our partnership with Square, Inc.
For security-related questions, vulnerability reports, or incident notifications, contact: security@logicdock.org
We acknowledge security reports within 48 hours and provide regular updates on remediation progress.