POLICY

Information Security & Data Protection Policy

How we protect the data entrusted to us, where it is processed, and what we do not claim.

VERSION 2.0. EFFECTIVE 4 AUGUST 2026. NEXT REVIEW 4 AUGUST 2027.

SolarisTech handles sensitive material: vessel certificates and survey records, class and flag correspondence, photographs taken on board, technical drawings, commercial documents and crew records. Most of it reaches us through the Nautilux AI secure upload portal. This policy states how we protect it, where it goes, who else touches it, how long we keep it, and what we do not claim. It applies to all SolarisTech information and systems and to everyone who accesses them. It should be read alongside our Privacy Policy, which deals with personal data specifically.

How we protect information

  • Encrypt client material in transit and at rest across our cloud infrastructure.
  • Require multi-factor authentication for administrative access and for the upload portal.
  • Segregate client workspaces so that one client's material is not visible to another.
  • Log access to client material, so that we can say who opened what and when.
  • Maintain backups and tested recovery for the systems our clients depend on.

Access on a need-to-know basis

  • Limit access to those who need it for a specific engagement, and remove it when the engagement closes or the person leaves.
  • Apply least-privilege by default and review permissions periodically.
  • Give contractors and attending surveyors access to the engagement they are working on, not to the platform at large.
  • Require personnel to protect their credentials and to report suspected compromise immediately.

Where client data is processed

Nautilux runs on Amazon Web Services and uses Microsoft Azure OpenAI Service. Material uploaded to the portal is stored in AWS. Text and images submitted for automated analysis are processed by Azure OpenAI Service in Microsoft's cloud. Those are the two places your material goes, and we will not add a third that handles client material without telling you first. The specific AWS and Azure regions used for your account are stated on request before you upload anything.

If your own obligations require processing to stay in a particular jurisdiction, raise it before onboarding so that we can confirm in writing whether we are able to meet it. Where we cannot, we will say so rather than accept the account.

Artificial intelligence processing of client material

Clients should know exactly what happens to a document they upload, so we state it plainly.

  • Documents, certificates, photographs and records uploaded to Nautilux are processed by automated analysis, including large language model and vision model processing delivered through Microsoft Azure OpenAI Service. That processing covers the whole submission, including photographs that may show identifiable individuals and documents that may contain crew personal data.
  • Microsoft's enterprise terms for Azure OpenAI Service state that customer content is not used to train Microsoft or OpenAI foundation models. We rely on those terms and can provide the current version on request. They are Microsoft's terms, not ours, and we do not warrant them.
  • Microsoft applies its own abuse monitoring to content submitted to the service. If your confidentiality requirements do not permit that, tell us before onboarding so we can address it.
  • We do not use client material to train models of our own without a separate written agreement with that client.
  • We do not sell client material, and we do not use one client's material to serve another, other than in aggregate and de-identified form to measure platform performance.
  • Automated analysis produces draft findings. It does not produce a final report on its own. A named SolarisTech reviewer checks findings before any report is issued, and the report identifies who reviewed it.
  • A client who needs automated analysis excluded from a submission should tell us before uploading. Some services cannot be delivered without it, and we will say so rather than quietly disable it.

Integrity of records

Where the integrity of a record matters, Nautilux keeps time-stamped, tamper-evident records of what was uploaded, what was analyzed, what was found and who reviewed it, so that audit and inspection evidence can be tested after the fact, including in a dispute. Preserving that chain is a core design and operating principle. We do not alter or remove an engagement record at any party's request without recording that we did so and at whose instruction.

Working with technology providers

  • We use a small, named set of sub-processors, listed in our Privacy Policy and provided in full at onboarding, and we assess each before entrusting it with data.
  • Data processing terms, confidentiality obligations and security obligations go into the contract with every provider.
  • We rely on the security certifications held by our infrastructure providers. Those are their certifications covering their platforms, not ours covering our controls.
  • We tell existing clients before adding a sub-processor that will handle their material.

Retention and deletion

Engagement material is retained for the period stated in the engagement documents. Where nothing else is agreed, our default is seven years from delivery of the final report, which reflects the limitation periods applicable to survey and inspection work and the record-keeping expectations of administrations, classification societies and insurers. A client may ask for uploaded material to be deleted earlier. We act on that request unless we are required to retain it by law, by a legal hold, or because a claim remains unresolved, and we tell you which of those applies.

Deletion covers primary storage and propagates to backups on the normal backup cycle. The final report, and the record that the engagement took place, are retained even where the source material is deleted.

Responding to incidents

We maintain procedures to detect, contain, investigate and recover from security incidents. Where an incident affects a client's material, we notify that client without undue delay and in any event within 72 hours of becoming aware of it, and we tell them what we know, what we do not yet know, and what we are doing about it. We notify regulators and affected individuals where the law requires it. We do not wait for a complete picture before telling a client that their material is involved.

What we are certified to, and what we are not

SolarisTech holds ISO 9001:2015 certification for its quality management system and ISO 21001:2018 certification for the educational management system covering SwiftAction Academy training. Both certificates are sent on request. We do not hold SOC 2 or ISO/IEC 27001 certification and we do not claim either. Our infrastructure providers hold their own certifications; those cover their platforms and not our controls. We make no certification claim in relation to information security.

We will complete a client security questionnaire, support a client-led assessment, and provide a written description of our controls on request. If a specific certification is a condition of your procurement process, tell us early so that neither side spends time on a process we cannot pass today.

This policy supports, and should be read alongside, our Privacy Policy. It is reviewed at least annually and after any material change to our systems, our providers or our obligations. Policy owner: Thomas H. Blenk, President and Chief Executive Officer. Security questionnaires, sub-processor lists and incident reports: admin@solaristechinc.com, marked for the attention of the President.

Questions About How We Work?

Ask for our certificates, our sub-processor list, our relationship and flag representation disclosures, or the scope of any engagement. We will send them.