Analytics cookies

We use Google Analytics and Microsoft Clarity to understand how our public website is used. They stay off unless you accept. Read our Cookie Policy.

Skip to content
Verified Crew logo
Security roadmap

Protecting the record your career runs on.

No badges we haven't earned.

Certificates, sea service, identity checks, and background results. The wallet holds the record your next job depends on, and this page shows exactly where its security certifications stand, stage by stage.

Shared with M/Y AuroraAll credentials valid
Verified Crew
Scan to verify
Portrait of Kai Andersen

Kai Andersen

Chief Officer

ID VerifiedBackground Cleared
Danish14 Mar 1996VC-887211

Where every certification stands today

ISO 27001PlannedGDPRPlannedPen testingPlannedSOC 2 Type 1PlannedSOC 2 Type 2Planned

Statuses update as each stage completes. Full detail below.

VerifiedCrew is built with security at its core. We pursue industry-leading certifications to demonstrate our commitment to protecting your credentials and meeting the highest standards of security, privacy, and compliance.

ISO 27001 Certificate badge
Planned

ISO 27001 Certificate

ISO 27001 is the international standard for information security management systems. It defines a documented framework for identifying, assessing, and treating information security risks.

Certification covers people, processes, and technology together: who has access to what, how security decisions are made, and how the controls are operated and reviewed. It is the certification most often required by enterprise buyers in Europe and Asia.

Started
2
In Progress
3
Policies
4
Audit
5
Granted
GDPR Compliance badge
Planned

GDPR Compliance

GDPR is the European Union regulation that governs how personal data is collected, stored, processed, and shared. It grants individuals the right to access, correct, export, and delete records held about them.

For credential platforms, the regulation covers identity verification results, background check outputs, employment history, and any other data that can identify a crew member. Compliance is required to operate in or process data from the EU and UK.

Started
2
In Progress
3
Policies
4
Audit
5
Granted
Penetration Testing badge
Planned

Penetration Testing

Penetration testing is an independent security assessment. An external firm uses the same techniques as a real attacker to find weaknesses in a platform before those weaknesses are exploited.

A typical engagement covers the web application, the API, and the supporting infrastructure. Findings are scored by severity, remediated, and re-tested. Annual testing is the baseline expectation for any platform that handles sensitive personal data.

Started
2
In Progress
3
Policies
4
Audit
5
Granted
SOC 2 Type 1 Certificate badge
Planned

SOC 2 Type 1 Certificate

SOC 2 Type 1 audits whether a platform has the right security, confidentiality, and availability controls in place at a single point in time. It is the entry-level SOC 2 report.

The audit covers how data is stored, who can access it, and how that access is governed. For credential management, that means certificates, sea time records, and verification data. Type 1 confirms the controls exist on the date the auditor checked.

Started
2
In Progress
3
Policies
4
Audit
5
Granted
SOC 2 Type 2 Certificate badge
Planned

SOC 2 Type 2 Certificate

SOC 2 Type 2 audits whether the same controls operate as designed over a six-month observation window. It is the report that enterprise compliance teams typically ask for.

The auditor reviews logs, change records, access reviews, and incident response across the period. Passing the audit means the controls did not just exist on paper, they ran reliably day after day.

Started
2
In Progress
3
Policies
4
Audit
5
Granted