Trust
Compliance + security posture.
What procurement teams need to clear vendor onboarding: regulatory regimes, GDPR posture, security controls, sub-processors, audit defensibility, and the Compliance Evidence Pack download.


Trust
Compliance and security posture
The posture procurement evaluators need to clear Provenship through vendor onboarding without back-and-forth. Read the eight sections below in three minutes, download the Compliance Evidence Pack, forward to legal and IT-security.
1. Regulatory regimes
Provenship computes obligations against the regulator-published instruments below. v1 in-scope regimes are listed first; UK ETS is on the roadmap. Verifier-acceptance posture is stated honestly — the platform is designed against verifier acceptance criteria, with the first letter of non-objection pending Release R1.
| Regime | Reference | Coverage | Verifier posture |
|---|---|---|---|
| FuelEU Maritime | Reg. (EU) 2023/1805 | v1 in-scope | Designed against acceptance; LNO pending R1 |
| EU ETS (shipping) | Directive 2003/87/EC (as amended) | v1 in-scope | Designed against acceptance; LNO pending R1 |
| EU MRV | Reg. (EU) 2015/757 | v1 in-scope | Designed against acceptance; LNO pending R1 |
| IMO DCS | MEPC.328(76) | v1 in-scope | Designed against acceptance; LNO pending R1 |
| IMO CII | MEPC.354(78) | v1 in-scope | Designed against acceptance; LNO pending R1 |
| UK ETS | UK ETS Order 2020 | Roadmap | Designed against acceptance; LNO pending R1 |
2. Data protection
Provenship operates under the EU GDPR (Reg. (EU) 2016/679) and the EUI Data Protection Regulation (Reg. (EU) 2018/1725). The posture below mirrors what the per-tenant DPA produces.
- Lawful basis
- Art. 6(1)(b) — processing necessary for performance of the service-provisioning contract with the tenant operator.
- DPIA determination (Art. 35)
- Not required for normal Provenship fleet processing. Vessels are not natural persons; crew names on BDNs are masked before LLM extraction. Per-tenant DPIA runs from /app/admin/dpia if a deployment escalates beyond baseline.
- Cross-border
- us-east-1 (NA tenants) and eu-west-1 (EU tenants) only. No Bedrock cross-region inference profiles — model invocations stay in-tenant-region per Core Principle 9.
- DSAR window
- One calendar month per Art. 12(3). Identity verification day 0-2; scope assembly day 2-21; signed export delivered day 21-30.
- Art. 30 ROPA
- Immutable audit log surfaces the Art. 30 record-of-processing-activities. Retention: 7 years (audit), 10 years (billing), 13 months (auth logs).
- Breach notification (Art. 33/34)
- 72-hour SLA to supervisory authority; high-risk-to-data-subject notification via BoldSign-signed templates against the supervisory-authority directory.
3. Security posture
Controls catalog. The Compliance Evidence Pack §4 expands each item with the underlying mechanism.
Encryption at rest
AWS KMS customer-managed keys for tenant data buckets.
Encryption in transit
TLS 1.3 for all external endpoints; TLS 1.2+ enforced at WAFv2.
Identity
AWS IAM Identity Center for staff; Cognito user pools for tenants.
MFA
Mandatory for all staff and for the OWNER_ADMIN, CFO, DPA tenant roles.
Hardware key
FIDO2 / WebAuthn required for the PLATFORM_ADMIN role.
RBAC (7 roles)
OWNER_ADMIN, CFO, DPA, TECHNICAL_MANAGER, POOL_ADMIN, VERIFIER, PLATFORM_ADMIN per spec 20.
Multi-tenant isolation (3 layers)
App filter by tenant_id from JWT, Postgres RLS independently, IAM-scoped Lambda roles where feasible.
Key management
AWS KMS with annual rotation; customer-managed keys for sensitive tenant buckets.
4. Sub-processors
Exhaustive list. The procurement email includes DPA links to each vendor; static disclosure here avoids stale links.
| Sub-processor | Purpose | Region |
|---|---|---|
| Cloud infrastructure provider | Compute, storage, identity, KMS | EU + US regions |
| LLM extraction service | Document extraction (BDN, voyage logs, monitoring plans) | EU + US regions |
| Verifier-signature platform | Verifier-signature workflow for emissions statements | EU + US |
| B2B multi-currency billing | B2B multi-currency billing (wire / SEPA / ACH) | EU + UK |
| Accounting + invoicing | Accounting and invoicing | EU + US |
| LLM observability (self-hosted) | LLM observability (in-tenant region only) | In-tenant region |
| EMSA THETIS-MRV (regulator) | Regulatory submission for EU MRV emissions reports | EU |
Explicitly NOT used
The marketing site loads no third-party analytics and sets no tracking cookies. Provenship does NOT use: Stripe, Google Analytics, Plausible, HubSpot, Calendly, Mixpanel, Segment.
5. Audit and breach defensibility
Two in-app surfaces back the procurement posture. Both are immutable, tenant-scoped, and queryable by the tenant DPA without an engineering ticket.
- /app/admin/audit-log — Art. 30 record-of-processing evidence; immutable ledger.
- /app/admin/breach-notifications — Art. 33 regulator notification + Art. 34 data-subject notification status tracking.
- Written policy: /legal/breach-notification-policy
6. Independence and neutrality
Provenship is not a verifier. The platform produces the artifact (signed PDF + snapshot hash + factor-set version + calculation-engine version) that an accredited independent verifier signs. There is no class-society lock-in: any accredited verifier (DNV, Lloyd's Register, Bureau Veritas, ClassNK, ABS, RINA, KR, etc.) can sign a Provenship-produced statement.
This separation is structural, not contractual — see ADR-027. The VERIFIER role is isolated from owner and operator roles by IAM scope; verifier users operate cross-tenant by design.
7. Get the bundle
Download the full Compliance Evidence Pack — a single PDF covering all eight sections above plus the GDPR Art. 30 ROPA extract, security controls catalog, DSAR procedure, breach notification procedure, DPIA Art. 35 determination, independence statement, and the Provenship core principles verbatim.
Generated client-side. Valid for procurement review only — not a regulator submission. 24-hour validity from generation timestamp.
8. Contact
Procurement-team direct questions go to the security inbox. Replies within one business day.