Trust Centre

Security, privacy, and how we protect your data

What is in place today, what has not yet been independently validated, and how to reach us with security questions.

Control summary reviewed 10 August 2026.

Data residency

EU application region

The primary application database and file storage are configured in Frankfurt, Germany through Supabase. Encrypted database exports use Cloudflare R2 with an EU location preference. Sub-processor details and any international-transfer safeguards are documented below and in the DPA.

Encryption

At rest and in transit

Application traffic is protected with TLS and HSTS. Supabase and Cloudflare provide storage-layer encryption at rest. Off-site database export files are additionally encrypted with age before upload to R2.

Authentication

Password + optional MFA

Authentication is provided through Supabase Auth. MANTIS supports email and password sign-in plus optional TOTP multi-factor authentication.

Data isolation

Per-vessel RLS

PostgreSQL row-level security scopes every query to the authenticated user's vessel, organisation, and shared-access grants at the database layer — not just the application layer.

Data ownership

Exportable by design

Customers can export working records, survey packs, transfer packages, audit history, and full archives that include uploaded evidence documents.

Auditability

Server-side event trails

Material changes, billing lifecycle events, export requests, and sensitive background processing are recorded server-side so support and compliance reviews have a traceable history.

Independent assurance

Current status

MANTIS does not yet hold SOC 2 or ISO 27001 certification and does not yet have an independent penetration-test report. Provider certifications are listed below.

Continuity

Daily off-site backups

Daily encrypted database exports are retained in Cloudflare R2 for 30 days and the decryption path has been tested. These exports cover database records, not uploaded Storage files; customer archive exports remain the file-portability route.

Documents

The full text of our public-facing security and compliance documents:

  • Privacy Policy — what data we collect, why, where it's stored, your rights.
  • Terms of Service — the contract that governs your use of MANTIS.
  • Data Processing Agreement — the GDPR Art. 28 processor agreement covering crew member data and other organisation-controlled data.
  • Service Provider Register — current sub-processors, other service providers, primary regions, and transfer safeguards.
  • Security Overview — the long-form description of our security posture, structured around NIST CSF 2.0.
  • security.txt — RFC 9116 machine-readable security contact.

Sub-processors

The current Customer Personal Data sub-processors are:

  • Supabase — database, authentication, storage. EU (Frankfurt). SOC 2 Type II.
  • Cloudflare — application delivery, DDoS protection, DNS, Turnstile, and encrypted database-export storage. Global edge network; R2 configured with an EU location preference. SOC 2 Type II.
  • Brevo (Sendinblue SAS) — transactional email. EU-based provider.
  • Functional Software Inc (Sentry) — application error monitoring. MANTIS EU data region (Germany). SOC 2 Type II.

Customers are notified at least 30 days in advance of any sub-processor change, with a right to object per the DPA.

Billing, MANTIS-controlled analytics, scheduling, and optional marketing analytics involve additional providers that are not Customer Personal Data sub-processors under the DPA. See the Service Provider Register for role definitions, primary regions, and international-transfer information.

Independent assurance

MANTIS itself does not currently hold SOC 2 or ISO 27001 certification and has not yet completed an independent web-application penetration test. We rely on documented internal controls and the independent certifications of our infrastructure providers:

  • Supabase, Cloudflare, Stripe, Sentry, PostHog — SOC 2 Type II
  • Stripe — PCI DSS Level 1

We will update this Trust Centre when MANTIS completes any independent certification or assessment. Until then, we will not present infrastructure-provider certifications as certifications of MANTIS itself.

Security FAQ

Where is my data stored?

The primary application database and uploaded-file storage are configured through Supabase in Frankfurt, Germany. Encrypted database exports use Cloudflare R2 with an EU location preference. MANTIS also uses the listed sub-processors for billing, email, monitoring, and analytics; the DPA and Privacy Policy describe those processing relationships and transfer safeguards.

Can I export my data?

Yes. The application includes Excel backups, survey pack exports, and full archive exports for account portability. Full archives are designed to include structured records and uploaded evidence documents, so vessel data remains usable outside MANTIS. GDPR Art. 20 requests can also be sent to privacy@mantis-ihm.com.

What happens to my data if I cancel?

Your access continues until the end of the current paid billing period. That date is the service termination date unless a separate customer agreement states otherwise. Customer Personal Data is then held only for export, return, or reactivation during a maximum 30-day transition window before deletion from production systems. You can request earlier deletion. Limited records may be retained where applicable law requires it, and automated database backups age out under their 30-day rotation.

Do you have a penetration test report?

Not yet. Our current security posture is documented in the Security Overview above. We are happy to discuss specific controls and concerns directly — email security@mantis-ihm.com.

Do you have an Incident Response Plan?

Yes. The plan defines severity levels, roles, detection channels, containment by incident type, customer notification without undue delay and in any event within 72 hours as required by the DPA, and post-incident review with anti-pattern feedback into our standards. Available to fleet prospects under NDA.

How do you protect against unauthorised access?

Three layers: authentication (email + password with optional MFA), authorisation (PostgreSQL RLS scopes every query to the user's vessel, organisation, and shared-access grants), and audit (material actions are logged with user, timestamp, and before/after state). Service-role database access is confined to server-side edge functions and never reaches the browser.

What if a sub-processor is breached?

We monitor sub-processor security advisories. If a breach affects MANTIS customer data, we notify customer organisations without undue delay and in any event within 72 hours of becoming aware, in line with the DPA. The Incident Response Plan covers our containment steps; the Data Breach Register records every event to support your GDPR Art. 33 reporting.


Reporting a vulnerability

If you believe you've found a security issue in MANTIS, please email security@mantis-ihm.com. PGP encryption is not required — clear English is more useful.

Please include: a description of the issue, the URL or component affected, steps to reproduce, and the impact you observed. If you can include a proof of concept, that helps us verify and prioritise. Do not include real customer data in your report.

What we commit to

  • Acknowledgement within 2 business days of receiving your report.
  • Initial triage within 5 business days with a severity assessment and indicative timeline.
  • Status updates at least weekly until the issue is resolved.
  • Public credit in a security advisory, if you wish, after a fix is shipped.

Critical issues, including unauthenticated access to customer data, account takeover, or remote code execution, receive immediate containment and remediation priority. The response timeline depends on the issue and the safest verified fix.

Safe harbour

We support good-faith security research. If you act in good faith and follow this policy, we will not pursue legal action against you. Specifically, we ask that you:

  • Test only against your own MANTIS account, not against other customers' data.
  • Stop testing and report immediately if you encounter personal data that isn't yours.
  • Do not perform denial-of-service testing, social engineering, or physical attacks.
  • Do not publicly disclose the vulnerability before we've had a reasonable chance to fix it (we'll agree a disclosure date with you).

Scope

In scope:

  • app.mantis-ihm.com — the MANTIS application
  • mantis-ihm.com — the marketing site
  • Public Supabase Edge Functions invoked by the application

Out of scope: third-party services we depend on (Supabase, Cloudflare, Stripe, Brevo, Sentry, PostHog, Plausible) — please report those directly to the respective vendors. Issues already publicly disclosed and on a published remediation timeline are also out of scope.

Contact

General / commercial: mantis-ihm.com/contact
Support: mantis-ihm.com/support
Security: security@mantis-ihm.com
Privacy / DPA: privacy@mantis-ihm.com
Registered entity: Navio Maritime OÜ, Estonian registry 17461120
Status page: mantis-ihm.com/status
security.txt: /.well-known/security.txt