Security Overview
MarineClaims Pro — claims assessment and marine asset survey platform
Effective 1 July 2026 · Version 3.0
Related: Privacy Policy · Data Processing Addendum · Subprocessors · Acceptable Use Policy · Terms of Service
1. Scope
This page summarises how Sustainable Transport Advisory Pty Ltd (“STA”) approaches security for MarineClaims Pro (“MCP”). It is a customer-facing overview, not a certification, guarantee, or detailed internal playbook.
MCP is a software tool. This page does not claim ISO 27001, SOC 2, NABERS, NGER or any other certification.
2. Shared responsibility
| STA | Customer |
|---|---|
| Secure the MCP application and infrastructure we control | Manage user accounts, roles and Portal invitations |
| Apply patches and monitoring on our stack | Choose strong passwords and keep credentials confidential |
| Process Customer Content under the DPA | Decide what data to upload and who may see it |
| Notify customers of relevant incidents as described in the DPA | Meet their own privacy and records duties |
3. Technical and organisational measures (high level)
STA maintains measures appropriate to the nature of MCP, including:
3.1 Encryption and transport
Industry-standard encryption for databases and stored files at rest, and encrypted connections in transit. Passwords are stored using strong one-way hashing.
3.2 Access control
- Role-based access inside MCP organisations;
- Least-privilege access for STA staff to production systems;
- Password sign-in, with email one-time codes for email verification, invitations and password reset;
- Logging of significant administrative actions where tooling supports it.
3.3 Network and hosting
- Application compute on a DigitalOcean droplet in Sydney (syd1);
- Managed Postgres and Redis on DigitalOcean in Sydney;
- Claim files, photos, PDFs and signatures stored with Cloudflare R2 (United States provider; storage location not locked to Australia) — see Subprocessors;
- Firewalling, network restrictions and environment separation (production vs non-production) as reasonably practicable;
- Automated backups provided by DigitalOcean Managed Postgres, with restricted access.
3.4 Application security practices
- Secure development practices appropriate to team size (code review, dependency updates, secret management);
- Vulnerability handling when issues are identified;
- Protection against common web application risks on a best-efforts basis.
3.5 People and process
- Confidentiality expectations for staff and contractors with access;
- Need-to-know access for customer support;
- Incident response steps: detect → contain → assess → notify → remediate (aligned with the Data Processing Addendum and Australian NDB duties where applicable).
3.6 AI and third-party processing
STA does not send Customer Content to third-party AI providers for processing. In-product help search uses on-server tooling without sending claim files to third-party AI providers.
4. Customer data access by STA
STA personnel access Customer Content only when needed to provide support, secure the platform, comply with law, or follow Customer instructions. Access is logged or reviewable where tooling allows.
5. Business continuity
STA uses managed database automated backups and recovery procedures designed to restore MCP within a commercially reasonable time after infrastructure failure. No specific uptime percentage is promised on this page unless stated in a signed Order or SLA.
6. Incident notification
If STA becomes aware of a security incident affecting Customer Content, STA will notify the Customer without undue delay as described in the Data Processing Addendum, and will meet Notifiable Data Breaches obligations where STA is the accountable APP entity for the affected information.
Customers should email support@sta-au.com immediately if they suspect unauthorised access to their MCP account.
7. Vulnerability reports
Responsible disclosure welcome at support@sta-au.com with enough detail to reproduce the issue. Do not access other tenants’ data or destroy data while testing.
8. Subprocessors
Infrastructure and service vendors that may Process Customer Content or related personal information are listed at Subprocessors.
9. Changes
STA may update this Overview as practices evolve. Material changes that affect commitments in the DPA will be reflected in the DPA or customer notice process.
10. Contact — The STA Team
support@sta-au.com · info@sta-au.com
Sustainable Transport Advisory Pty Ltd, ABN 75 657 423 222, Newport VIC 3015
https://app.marineclaimspro.com
— The STA Team
