Security & Compliance

Learn about Guest Trip's security practices, SOC 2 Type II compliance, GDPR readiness and how charter guest data is protected.

How guest and crew data is protected

Guest Trip treats charter data as confidential by default. All traffic is encrypted in transit, data is encrypted at rest, and every record is scoped to the organisation that owns it and enforced at the database level, so one charter operation can never read another's itineraries, guests or crew. Guest-facing sites are reached only through a private link and PIN, and sensitive details such as network passwords and crew contact information are never exposed in guest responses.

Access control and authentication

Crew accounts use email and password or Google sign-in, with role-based permissions so each team member sees only what their role requires. Two-factor authentication is available, administrative access is restricted and separately audited, and privileged actions are recorded in an audit log for review.

Compliance and privacy

Our controls are aligned to SOC 2 Type II criteria and the platform is built for GDPR compliance, with the charter operator acting as data controller and Guest Trip as processor. Guests can be given itineraries without storing unnecessary personal data, personal data can be exported or deleted on request, and our subprocessors are disclosed to customers.

Resilience and responsible disclosure

Infrastructure is hosted with established cloud providers in managed data centres, with automated backups, monitoring and dependency scanning. Security findings are triaged and remediated on a defined schedule, and anyone who believes they have found a vulnerability can report it to us directly for prompt investigation.

Data Protection

  • AES-256 encryption at rest for all stored data
  • TLS 1.3 encryption for all data in transit
  • Hosted on SOC 2 compliant cloud infrastructure
  • Database-level row-level security (RLS) on every table
  • Automated encrypted backups with point-in-time recovery

Access Control

  • Role-based access control (RBAC) with organisation-level isolation
  • Multi-factor authentication (MFA) support
  • Session management with activity tracking
  • Principle of least privilege enforced via database policies
  • Secure password hashing with bcrypt

Audit & Monitoring

  • Comprehensive audit logging on all sensitive operations
  • Automated triggers capturing create, update, and delete events
  • Privileged action tracking (role changes, account deletions)
  • Real-time anomaly monitoring and alerting
  • Minimum 365-day log retention for compliance

Compliance

  • SOC 2 Type II — controls for security, availability, and confidentiality
  • GDPR — data subject rights, lawful processing, and data minimisation
  • Regular third-party penetration testing and vulnerability assessments
  • Annual compliance audits and certifications

Data Retention & Deletion

  • Configurable data retention policies per organisation
  • Secure account deletion with full data purge
  • Automated retention enforcement for compliance audit logs
  • Right to erasure (GDPR Article 17) supported
  • Deletion audit trail maintained for compliance verification

Incident Response

  • Dedicated security incident response team
  • 72-hour breach notification (GDPR requirement)
  • Documented incident response and escalation procedures
  • Post-incident analysis and remediation tracking
  • All automated communications originate exclusively from notifications@app.guest-trip.com — any email from a different address is not from us
  • Contact: contact@guest-trip.com

Subprocessors and security enquiries

Guest Trip uses a limited number of vetted service providers for cloud infrastructure, email, messaging, payments, mapping, vessel tracking and AI-assisted content. Each provider is reviewed for its security controls, data handling and compliance posture, and account holders can access the detailed subprocessor list.

Customers can contact the Guest Trip security team to ask about security practices, request the available compliance information or report a suspected vulnerability.