Skip to main content

Trust

Compliance + security posture.

What procurement teams need to clear vendor onboarding: regulatory regimes, GDPR posture, security controls, sub-processors, audit defensibility, and the Compliance Evidence Pack download.

Institutional regulatory facade — compliance posture visual
Soft-focus interior of a formal European regulatory chamber at dusk with an EU flag in the background.

Trust

Compliance and security posture

The posture procurement evaluators need to clear Provenship through vendor onboarding without back-and-forth. Read the eight sections below in three minutes, download the Compliance Evidence Pack, forward to legal and IT-security.

1. Regulatory regimes

Provenship computes obligations against the regulator-published instruments below. v1 in-scope regimes are listed first; UK ETS is on the roadmap. Verifier-acceptance posture is stated honestly — the platform is designed against verifier acceptance criteria, with the first letter of non-objection pending Release R1.

RegimeReferenceCoverageVerifier posture
FuelEU MaritimeReg. (EU) 2023/1805v1 in-scopeDesigned against acceptance; LNO pending R1
EU ETS (shipping)Directive 2003/87/EC (as amended)v1 in-scopeDesigned against acceptance; LNO pending R1
EU MRVReg. (EU) 2015/757v1 in-scopeDesigned against acceptance; LNO pending R1
IMO DCSMEPC.328(76)v1 in-scopeDesigned against acceptance; LNO pending R1
IMO CIIMEPC.354(78)v1 in-scopeDesigned against acceptance; LNO pending R1
UK ETSUK ETS Order 2020RoadmapDesigned against acceptance; LNO pending R1

2. Data protection

Provenship operates under the EU GDPR (Reg. (EU) 2016/679) and the EUI Data Protection Regulation (Reg. (EU) 2018/1725). The posture below mirrors what the per-tenant DPA produces.

Lawful basis
Art. 6(1)(b) — processing necessary for performance of the service-provisioning contract with the tenant operator.
DPIA determination (Art. 35)
Not required for normal Provenship fleet processing. Vessels are not natural persons; crew names on BDNs are masked before LLM extraction. Per-tenant DPIA runs from /app/admin/dpia if a deployment escalates beyond baseline.
Cross-border
us-east-1 (NA tenants) and eu-west-1 (EU tenants) only. No Bedrock cross-region inference profiles — model invocations stay in-tenant-region per Core Principle 9.
DSAR window
One calendar month per Art. 12(3). Identity verification day 0-2; scope assembly day 2-21; signed export delivered day 21-30.
Art. 30 ROPA
Immutable audit log surfaces the Art. 30 record-of-processing-activities. Retention: 7 years (audit), 10 years (billing), 13 months (auth logs).
Breach notification (Art. 33/34)
72-hour SLA to supervisory authority; high-risk-to-data-subject notification via BoldSign-signed templates against the supervisory-authority directory.

3. Security posture

Controls catalog. The Compliance Evidence Pack §4 expands each item with the underlying mechanism.

  • Encryption at rest

    AWS KMS customer-managed keys for tenant data buckets.

  • Encryption in transit

    TLS 1.3 for all external endpoints; TLS 1.2+ enforced at WAFv2.

  • Identity

    AWS IAM Identity Center for staff; Cognito user pools for tenants.

  • MFA

    Mandatory for all staff and for the OWNER_ADMIN, CFO, DPA tenant roles.

  • Hardware key

    FIDO2 / WebAuthn required for the PLATFORM_ADMIN role.

  • RBAC (7 roles)

    OWNER_ADMIN, CFO, DPA, TECHNICAL_MANAGER, POOL_ADMIN, VERIFIER, PLATFORM_ADMIN per spec 20.

  • Multi-tenant isolation (3 layers)

    App filter by tenant_id from JWT, Postgres RLS independently, IAM-scoped Lambda roles where feasible.

  • Key management

    AWS KMS with annual rotation; customer-managed keys for sensitive tenant buckets.

4. Sub-processors

Exhaustive list. The procurement email includes DPA links to each vendor; static disclosure here avoids stale links.

Sub-processorPurposeRegion
Cloud infrastructure providerCompute, storage, identity, KMSEU + US regions
LLM extraction serviceDocument extraction (BDN, voyage logs, monitoring plans)EU + US regions
Verifier-signature platformVerifier-signature workflow for emissions statementsEU + US
B2B multi-currency billingB2B multi-currency billing (wire / SEPA / ACH)EU + UK
Accounting + invoicingAccounting and invoicingEU + US
LLM observability (self-hosted)LLM observability (in-tenant region only)In-tenant region
EMSA THETIS-MRV (regulator)Regulatory submission for EU MRV emissions reportsEU

Explicitly NOT used

The marketing site loads no third-party analytics and sets no tracking cookies. Provenship does NOT use: Stripe, Google Analytics, Plausible, HubSpot, Calendly, Mixpanel, Segment.

5. Audit and breach defensibility

Two in-app surfaces back the procurement posture. Both are immutable, tenant-scoped, and queryable by the tenant DPA without an engineering ticket.

  • /app/admin/audit-log — Art. 30 record-of-processing evidence; immutable ledger.
  • /app/admin/breach-notifications — Art. 33 regulator notification + Art. 34 data-subject notification status tracking.
  • Written policy: /legal/breach-notification-policy

6. Independence and neutrality

Provenship is not a verifier. The platform produces the artifact (signed PDF + snapshot hash + factor-set version + calculation-engine version) that an accredited independent verifier signs. There is no class-society lock-in: any accredited verifier (DNV, Lloyd's Register, Bureau Veritas, ClassNK, ABS, RINA, KR, etc.) can sign a Provenship-produced statement.

This separation is structural, not contractual — see ADR-027. The VERIFIER role is isolated from owner and operator roles by IAM scope; verifier users operate cross-tenant by design.

7. Get the bundle

Download the full Compliance Evidence Pack — a single PDF covering all eight sections above plus the GDPR Art. 30 ROPA extract, security controls catalog, DSAR procedure, breach notification procedure, DPIA Art. 35 determination, independence statement, and the Provenship core principles verbatim.

Generated client-side. Valid for procurement review only — not a regulator submission. 24-hour validity from generation timestamp.

8. Contact

Procurement-team direct questions go to the security inbox. Replies within one business day.

security [at] provenship.com