Trust & security

Security built around maritime accountability

MusterDeck is designed so operational records are accessed through defined roles, company and vessel scopes, audited workflows and controlled sharing. Security controls continue to be tested as the platform develops.

Role-based access

Permissions are evaluated by role and operational scope so users can be limited to the companies, vessels and functions they are authorised to use.

Company and vessel separation

Sensitive workflows use authenticated, scoped backend functions and row-level rules to reduce the risk of records crossing company or vessel boundaries.

Audit trails

Security-sensitive and compliance-sensitive actions are recorded so authorised teams can review who performed an action and when.

Controlled external sharing

Inspection and report-sharing workflows use deliberately selected content, revocable links, expiry controls and optional password protection where supported.

Authentication and account controls

MusterDeck uses authenticated accounts for operational access. Invitation and setup flows use scoped tokens and account-security controls rather than shared fleet passwords.

Offline permission revalidation

Authorised offline-capable work can be stored locally and queued for synchronisation; supported queued changes are rechecked by the server when connectivity returns.

Responsible disclosure

If you believe you have found a security issue, do not attempt to access data that is not yours. Contact the MusterDeck team with the affected page, the behaviour observed and enough detail for us to reproduce it safely.

Important scope note

This page describes current product controls at a high level. It is not a certification, penetration-test report or claim of compliance with a specific external security standard unless MusterDeck separately provides evidence for that claim.