# Security of this website

This page states the **law, rules, regulations and security baselines** used to design the public website. It does not describe implementation technology, and it is not a certificate.

The origin is a public information and quotation site. It does not hold client dossiers, manifests, crew lists or ship security plans. A government buyer can treat it as a BIO2-supporting public website. It is not a case-management system and not an organisation-wide information security management system.

Secure Sail Solutions is a private company established in the Netherlands. Some instruments below are **binding on Dutch public-sector buyers**. We used them so those buyers can take this site as an input to their own BIO2 and Forum Standaardisatie obligations. That is not a claim that Secure Sail is a government body, that we hold ISO/IEC 27001 certification, or that we are designated under the Cyberbeveiligingswet.

## Law and regulation

**General Data Protection Regulation (GDPR) / Algemene verordening gegevensbescherming (AVG).** This origin does not set cookies, does not profile visitors, and does not collect personal data through a form. Enquiries are by email. Legal bases and rights are on the [privacy](/privacy/) page.

**Dutch cookie rules (Telecommunicatiewet).** A cookieless public site that does not store or track does not require a consent banner.

**DigiToegankelijk / Wet digitale overheid.** WCAG 2.1 Level AA is the legal accessibility floor for Dutch public-sector websites. This origin also meets the extra WCAG 2.2 AA criteria that apply to a static site. Statement: [accessibility](/accessibility/).

**NIS2 Directive (EU) 2022/2555 and the Dutch Cyberbeveiligingswet.** BIO2 is aligned with NIS2 Article 21 (cybersecurity risk-management measures). This page does **not** assert that Secure Sail is an essential or important entity under that Act.

**Forum Standaardisatie (‘pas toe of leg uit’).** For Dutch public bodies: HTTPS, current TLS, DNSSEC, IPv6, and email authentication. The production name of this site is built so those open standards can be applied. [Internet.nl](https://internet.nl/) measures them on the **live hostname**. A score is published there after DNS cutover; this page does not invent one.

## Information-security baselines used

**Baseline Informatiebeveiliging Overheid 2 (BIO2),** current published version (v1.3, 2026). The Dutch government information-security baseline for all layers of government. BIO2 complements, and does not replace, ISO/IEC 27001 and 27002. We used it as the design baseline for a public-sector-facing website: EU data residency for production, cryptography in transit, logging without unnecessary personal data, least privilege (no accounts on this origin), and no client files on the public site. BIO2 is an **organisation** framework. This origin can support a buyer’s BIO2 controls. It is not a BIO2 declaration for Secure Sail as a whole.

**NEN-EN-ISO/IEC 27001:2023.** Requirements for an information security management system (ISMS). This website is one information asset in that picture. We do not claim ISO/IEC 27001 certification.

**NEN-EN-ISO/IEC 27002:2022.** Control catalogue on which BIO2 part 2 is structured. Applied here where a public website has a surface: cryptography, logging and monitoring, supplier relationship for published files, reduction of unused attack surface, and secure configuration of the public origin.

**OWASP Application Security Verification Standard (ASVS) 4.0.3, Level 2.** The verification level used for this origin. Fourteen chapters were mapped. Authentication, session management and multi-tenant access control have **no surface** here (no login, no sessions, no tenants). Those chapters are recorded as not applicable, not as implemented theatre. If a later quotation or CRM system is built, it is a separate EU-hosted system and must be verified in its own right.

**OWASP Top 10** was not used as the ceiling. Level 2 of ASVS is the bar that was applied.

**NCSC-NL ICT-beveiligingsrichtlijnen voor Transport Layer Security (2025-05).** Production transport security follows this guideline: TLS 1.3 (classification Good) and TLS 1.2 (classification Sufficient). Older protocol versions are not offered.

**NCSC-NL ICT-beveiligingsrichtlijnen voor webapplicaties.** Used as the Dutch web-application security guideline for a public site (strict content security, no unnecessary third-party processing, no unused write interface on this origin).

**NIST SP 800-53 Revision 5 and NIST Cybersecurity Framework 2.0.** Used as a comparable international control set. The NCSC web-application guidelines map to ISO/IEC 27002 and to NIST SP 800-53. This is not a US federal authorization to operate.

**RFC 9116 (security.txt)** and the **NCSC coordinated vulnerability disclosure** practice. How to report a finding is below.

## What we designed the origin to do

- Remain a read-only public site. Quotations are requested by email, not by writing to this origin.
- Avoid cookies, tracking and third-party content so GDPR and the Dutch cookie rules stay in the simplest lawful pattern.
- Keep personal and operational data off this host. IMO numbers in a first request are public hull identifiers; manifests, crew lists and security plans are not accepted here.
- Host production in the European Union so a BIO2 buyer can treat data residency as inside the Union.
- Log enough to support BIO2 audit of the public origin without recording query strings, cookies or other unnecessary personal data.
- Publish a machine-readable disclosure contact.

## What this page does not claim

- ISO/IEC 27001 or 27002 certification.
- A completed BIO2 statement for the organisation.
- That Secure Sail is in scope of the Cyberbeveiligingswet.
- A 100 percent Internet.nl result before the production name is live.
- We do not claim that risk is eliminated, or that using this site makes a buyer legally compliant.

## Vulnerability disclosure

Report suspected vulnerabilities to [privacy@securesailsolutions.com](mailto:privacy@securesailsolutions.com). Machine-readable contact: [/.well-known/security.txt](/.well-known/security.txt) (RFC 9116). Please follow coordinated disclosure: give us a reasonable period to investigate before public detail. Do not include client dossiers or security plans in a first report.
