Who this is for: the programme lead, the institution's IT or security reviewer, and anyone answering a funder's or a regulator's questions about the data.
Where it runs
Where Nebli hosts Marine, it runs in Nebli's own AWS account in one US region, on the same managed cluster as Nebli's other products but in its own namespace, with its own database and message stream; it shares no code, database or application service with them. The address is marine.nebli.ai; gateways connect to mqtt.marine.nebli.ai on port 8883.
Your organisation's data stays yours
- Every read and write is scoped to one organisation. The organisation comes from the person's session or the gateway's credential, never from the request. An id from another organisation answers exactly as a missing one.
- A gateway writes only into its own campaign. A drifter heard by another organisation's gateway becomes that organisation's own node and never touches yours.
- The service cannot change the record. The database grants the service only the right to add readings and audit rows and to read them, never to change or delete them. A correction is another reading.
- Exports reach only the person who asked, after the same role and organisation checks as any read. There is never a public or shareable link to an export.
- Live data carries only your organisation, and the session is checked again about once a minute.
Protection in transit and at rest
- In transit: every connection from outside uses TLS. Plain HTTP is only redirected to HTTPS, and the gateway port takes TLS only. Browsers are told to use HTTPS only.
- At rest: the database and the file store use the cloud platform's encryption at rest. Exports are kept in a private store under keys that include the organisation, and every read of one checks it.
- Credentials: a gateway credential's secret is shown once and stored only as a keyed hash (HMAC). The gateway program keeps it in a file only its own user can read, and refuses to start otherwise.
- Logs never hold a credential, a sign-in code, a token or anything from a request header.
Signing in
There are no passwords. A person signs in with an eight-character code sent to their email, which works once, for ten minutes, in the browser that asked for it. Repeated wrong codes spend the code, and limits apply per address and per network, but an address is never locked. A session lasts up to 8 hours and ends after 30 minutes without use. Each person's role is read again on every request, so a change or a removal takes effect at once (People and access).
Backups
The database is backed up continuously, with a full backup four times a day, to separate storage that the database itself cannot delete from. Backups are kept for 35 days, so any point in the last 30 days can be restored. Readings that arrived but were not yet saved when the service failed are replayed from the inbound stream, which keeps the last 24 hours.
Firmware and the gateway program
- Firmware and the gateway program are built only by Nebli's release pipeline from a tagged version, and signed with a key that cannot be exported.
- The flash page checks the signature and every image's checksum before a byte reaches the board, and refuses otherwise.
- You can check a gateway download yourself against the published key:
openssl dgst -sha256 -verify release-key.pem -signature SHA256SUMS.sig SHA256SUMS, thensha256sum -c SHA256SUMS. The key's fingerprint (SHA-256 of the public key, DER) is611943c24df2f671dd523231bc2861e3dc767afd829eaf32e9d44145f27a5eff. - Boards take no remote login: no Wi-Fi, no Bluetooth, no over-the-air update, and configuration over USB only.
Limits you should know
- Mesh readings are not signed. A radio within range of a gateway could send readings into that campaign, and Nebli Marine cannot tell them from a drifter's own. Such readings can land only in that gateway's campaign, and every mesh reading carries the source mesh in the record and in exports. State this when you present results from mesh readings (The record and methods).
- Anyone in radio range can read a drifter's recent reports: its track and sensor values over about the last day, the same readings it sends the gateway. The readings carry no secret. Repeated requests can also cost the drifter battery.
- The firmware version on a reading is the board's own report; the board does not prove it cryptographically.
What Nebli records about use
Where Nebli hosts Marine, it records product analytics and a replay of signed-in sessions, to see how a programme uses the product.
- Recorded: what a person did (for example signed in, invited someone, issued or revoked a credential, started or ended a campaign or launch, adopted or marked a drifter, asked for or downloaded an export), with ids, fixed values and counts only, and the screens as the person saw them, readings included.
- Never recorded: the sign-in, invitation and flash pages, and a gateway credential's secret with its copy button. No event carries a reading, a name, an email, a label, a note or any typed text.
- The signed-in person's email is attached to their sessions so a replay shows who it is, except in an organisation whose contract has Nebli process its people's data on its behalf without naming product analytics. There, people are identified by an opaque id only.
Personal data
Nebli Marine holds people's emails, names and languages, and the audit rows that name them. When a person is removed, their row is kept and marked removed, so the audit can always say who did what; nothing is erased.
Compliance
Nebli Marine has not been audited or certified against a security framework such as SOC 2 or ISO 27001.
Next
- People and access: roles, invitations and sign-in.
- The record and methods: what every reading keeps, and the audit.