Security & Compliance Initiatives 2026β2027 Β· March 24, 2026 Β· Document Version: 1.0
PortFlow is committed to the highest standards of data security and regulatory compliance. This public roadmap outlines our security and compliance initiatives for 2026 and 2027, demonstrating our commitment to security-conscious maritime agencies.
We believe transparency about our security roadmap builds trust. This is what we're building, and when you can expect it.
Q1
Foundation
Q2
Enhancement
Q3
Assessment
Q4
Certification
Focus: Publish security documentation and establish baseline compliance
Delivered
In Progress
Focus: Finalize compliance agreements and plan certification audits
Formal GDPR compliance contract for customers. Currently in legal review.
Data stored in AWS eu-west-1 (Ireland) for EU customers. Infrastructure planning stage.
Automated systems for data access/deletion requests. Testing in progress.
Formal evaluation of Neon, Vercel, Anthropic security posture.
Verify data can be recovered from backups. Procedures documented.
Additional detail for customers and auditors. Currently outlined.
Key Dates
Focus: Conduct independent security assessment and strengthen controls
External firm tests full application and infrastructure. Vendor selection in progress. Penetration test report with findings will be delivered.
Fix any vulnerabilities found in penetration test. Procedures defined.
Improved audit trails for compliance auditors. Design completed.
Documented procedures for security incidents. Currently drafted.
Ensure all staff understand security requirements. Curriculum designed.
Customer Impact
The penetration test identifies vulnerabilities before customers discover them. Results will be shared transparently with a remediation plan included.
Focus: Complete GDPR audit and begin SOC 2 Type II audit
Independent auditor verifies full GDPR compliance. Scope: lawful basis, data subject rights, security measures, sub-processor compliance. Estimated cost: β¬15,000ββ¬25,000. Report due January 2027.
SOC 2 Type II is the gold standard for SaaS security. 6-month audit period verifying Security, Availability, and Integrity controls. Planning phase begins Q4.
All security vulnerabilities from Q3 penetration test patched.
Share audit reports with customers as appropriate. Process defined.
Update Privacy Policy and Security Whitepaper based on audit findings.
What Customers Get by End of Q4 2026
Certifications by End of 2027
β SOC 2 Type II (March 2027)
β GDPR Compliant (January 2027)
β³ ISO 27001 (planning phase, 2027β2028)
All dates reflect industry standards for certification timelines, actual audit durations, and team resource requirements.
Each item has defined scope, clear ownership, measurable outcomes, and contingency buffer for delays.
We avoid claiming certifications we don't have, publishing reports that don't exist, or compressing timelines unrealistically.
If we cannot meet a deadline, we will notify affected customers immediately, provide a revised timeline, explain what delayed the work, and share interim progress reports.
Current Customers
Review this roadmap for items that matter to your organization. Share feedback on priorities.
Prospective Customers
Use this roadmap to evaluate our security maturity. Request current audit reports or DPA.
Security / Compliance Teams
Review supporting documentation. Schedule a security assessment call with our team.
PortFlow Β© 2026 Β· All Rights Reserved Β· Document Version 1.0 Β· Latest updates at portflow.tech/roadmap