Updated August 23, 2026
An agency hands its software the things it cannot afford to lose: what it charges, who it works for, and the identity papers of people at sea. That is a lot of trust to ask for, so here is what you get for it, in plain language and without the jargon.
Several agencies run on PortFlow, and none of them can see another's work. That separation is not a setting somebody has to remember to switch on. It is built into the foundation, so a request that has no business seeing your records comes back with nothing at all.
Passport numbers, visas and seaman's books are the most sensitive thing an agency holds, and they belong to people who never signed up for anything. They are encrypted before they are stored, with the key kept apart from the data, so even a copy of the storage gives up nothing readable.
Two-step sign-in is available on every account. Repeated guessing gets shut down rather than left to run. Sessions time out on their own and cannot be stretched forever, and an old one that turns up somewhere else ends the session instead of quietly working.
Vessels, quotations, invoices, crew records and administrative changes all leave a trace: who did it, in which agency, and when. The next time a client disputes a figure or an auditor asks who approved a discount, the answer is in the file. You can take that trail out of the product yourself.
Administration, management, operations, sales and audit see the part of the port call that belongs to them. The check happens on our side of the wire, so it is never a matter of a button being hidden. Audit reviews everything and changes nothing.
PortFlow runs on infrastructure from providers that are independently certified. That covers their part, not ours. PortFlow does not hold a certification of its own, and we would rather tell you that here than let the hosting imply something we have not earned. If a certification is a requirement for your business rather than a preference, say so early and we will tell you honestly where that leaves us.
They should have it, and this page is not the place for it. Write to security@portflow.tech and we answer technical due-diligence questionnaires directly, in whatever format your process uses.
The IMO guidance on maritime cyber risk management applies to agencies and operators rather than to their software suppliers, so that obligation stays with you. What we can account for is the software part: how your operational data is protected, who can reach it, and what record exists of every change.
A 14-day trial opens a full workspace. Create a port call, issue a quotation, run a crew document check, and go look at exactly what landed in the trail afterwards. Nothing on this page is planned or coming soon; it is the same product a paying agency uses.
Start your 14-day trialNo credit card required