Protecting the record
your career runs on.
No badges we haven't earned.
Certificates, sea service, identity checks, and background results. The wallet holds the record your next job depends on, and this page shows exactly where its security certifications stand, stage by stage.
Kai Andersen
Chief Officer
Where every certification stands today
Statuses update as each stage completes. Full detail below.
VerifiedCrew is built with security at its core. We pursue industry-leading certifications to demonstrate our commitment to protecting your credentials and meeting the highest standards of security, privacy, and compliance.

ISO 27001 Certificate
ISO 27001 is the international standard for information security management systems. It defines a documented framework for identifying, assessing, and treating information security risks.
Certification covers people, processes, and technology together: who has access to what, how security decisions are made, and how the controls are operated and reviewed. It is the certification most often required by enterprise buyers in Europe and Asia.

GDPR Compliance
GDPR is the European Union regulation that governs how personal data is collected, stored, processed, and shared. It grants individuals the right to access, correct, export, and delete records held about them.
For credential platforms, the regulation covers identity verification results, background check outputs, employment history, and any other data that can identify a crew member. Compliance is required to operate in or process data from the EU and UK.

Penetration Testing
Penetration testing is an independent security assessment. An external firm uses the same techniques as a real attacker to find weaknesses in a platform before those weaknesses are exploited.
A typical engagement covers the web application, the API, and the supporting infrastructure. Findings are scored by severity, remediated, and re-tested. Annual testing is the baseline expectation for any platform that handles sensitive personal data.

SOC 2 Type 1 Certificate
SOC 2 Type 1 audits whether a platform has the right security, confidentiality, and availability controls in place at a single point in time. It is the entry-level SOC 2 report.
The audit covers how data is stored, who can access it, and how that access is governed. For credential management, that means certificates, sea time records, and verification data. Type 1 confirms the controls exist on the date the auditor checked.

SOC 2 Type 2 Certificate
SOC 2 Type 2 audits whether the same controls operate as designed over a six-month observation window. It is the report that enterprise compliance teams typically ask for.
The auditor reviews logs, change records, access reviews, and incident response across the period. Passing the audit means the controls did not just exist on paper, they ran reliably day after day.






