Security of this website

This page states the law, rules, regulations and security baselines used to design the public website. It does not describe implementation technology, and it is not a certificate.

The origin is a public information and quotation site. It does not hold client dossiers, manifests, crew lists or ship security plans. A government buyer can treat it as a BIO2-supporting public website. It is not a case-management system and not an organisation-wide information security management system.

Secure Sail Solutions is a private company established in the Netherlands. Some instruments below are binding on Dutch public-sector buyers. We used them so those buyers can take this site as an input to their own BIO2 and Forum Standaardisatie obligations. That is not a claim that Secure Sail is a government body, that we hold ISO/IEC 27001 certification, or that we are designated under the Cyberbeveiligingswet.

Law and regulation

General Data Protection Regulation (GDPR) / Algemene verordening gegevensbescherming (AVG). This origin does not set cookies, does not profile visitors, and does not collect personal data through a form. Enquiries are by email. Legal bases and rights are on the privacy page.

Dutch cookie rules (Telecommunicatiewet). A cookieless public site that does not store or track does not require a consent banner.

DigiToegankelijk / Wet digitale overheid. WCAG 2.1 Level AA is the legal accessibility floor for Dutch public-sector websites. This origin also meets the extra WCAG 2.2 AA criteria that apply to a static site. Statement: accessibility.

NIS2 Directive (EU) 2022/2555 and the Dutch Cyberbeveiligingswet. BIO2 is aligned with NIS2 Article 21 (cybersecurity risk-management measures). This page does not assert that Secure Sail is an essential or important entity under that Act.

Forum Standaardisatie (‘pas toe of leg uit’). For Dutch public bodies: HTTPS, current TLS, DNSSEC, IPv6, and email authentication. The production name of this site is built so those open standards can be applied. Internet.nl measures them on the live hostname. A score is published there after DNS cutover; this page does not invent one.

Information-security baselines used

Baseline Informatiebeveiliging Overheid 2 (BIO2), current published version (v1.3, 2026). The Dutch government information-security baseline for all layers of government. BIO2 complements, and does not replace, ISO/IEC 27001 and 27002. We used it as the design baseline for a public-sector-facing website: EU data residency for production, cryptography in transit, logging without unnecessary personal data, least privilege (no accounts on this origin), and no client files on the public site. BIO2 is an organisation framework. This origin can support a buyer’s BIO2 controls. It is not a BIO2 declaration for Secure Sail as a whole.

NEN-EN-ISO/IEC 27001:2023. Requirements for an information security management system (ISMS). This website is one information asset in that picture. We do not claim ISO/IEC 27001 certification.

NEN-EN-ISO/IEC 27002:2022. Control catalogue on which BIO2 part 2 is structured. Applied here where a public website has a surface: cryptography, logging and monitoring, supplier relationship for published files, reduction of unused attack surface, and secure configuration of the public origin.

OWASP Application Security Verification Standard (ASVS) 4.0.3, Level 2. The verification level used for this origin. Fourteen chapters were mapped. Authentication, session management and multi-tenant access control have no surface here (no login, no sessions, no tenants). Those chapters are recorded as not applicable, not as implemented theatre. If a later quotation or CRM system is built, it is a separate EU-hosted system and must be verified in its own right.

OWASP Top 10 was not used as the ceiling. Level 2 of ASVS is the bar that was applied.

NCSC-NL ICT-beveiligingsrichtlijnen voor Transport Layer Security (2025-05). Production transport security follows this guideline: TLS 1.3 (classification Good) and TLS 1.2 (classification Sufficient). Older protocol versions are not offered.

NCSC-NL ICT-beveiligingsrichtlijnen voor webapplicaties. Used as the Dutch web-application security guideline for a public site (strict content security, no unnecessary third-party processing, no unused write interface on this origin).

NIST SP 800-53 Revision 5 and NIST Cybersecurity Framework 2.0. Used as a comparable international control set. The NCSC web-application guidelines map to ISO/IEC 27002 and to NIST SP 800-53. This is not a US federal authorization to operate.

RFC 9116 (security.txt) and the NCSC coordinated vulnerability disclosure practice. How to report a finding is below.

What we designed the origin to do

  • Remain a read-only public site. Quotations are requested by email, not by writing to this origin.
  • Avoid cookies, tracking and third-party content so GDPR and the Dutch cookie rules stay in the simplest lawful pattern.
  • Keep personal and operational data off this host. IMO numbers in a first request are public hull identifiers; manifests, crew lists and security plans are not accepted here.
  • Host production in the European Union so a BIO2 buyer can treat data residency as inside the Union.
  • Log enough to support BIO2 audit of the public origin without recording query strings, cookies or other unnecessary personal data.
  • Publish a machine-readable disclosure contact.

What this page does not claim

  • ISO/IEC 27001 or 27002 certification.
  • A completed BIO2 statement for the organisation.
  • That Secure Sail is in scope of the Cyberbeveiligingswet.
  • A 100 percent Internet.nl result before the production name is live.
  • We do not claim that risk is eliminated, or that using this site makes a buyer legally compliant.

Vulnerability disclosure

Report suspected vulnerabilities to privacy@securesailsolutions.com. Machine-readable contact: /.well-known/security.txt (RFC 9116). Please follow coordinated disclosure: give us a reasonable period to investigate before public detail. Do not include client dossiers or security plans in a first report.