Skip to main content
GT Connect Maritime collaboration platform
Trust centre

Security at GT Connect

GT Connect is developed and operated by Global Technology Ltd, trading as GTMaritime. The production service is hosted in GTMaritime's Amazon Web Services environment and managed under the same certified information-security programme as GTMaritime's other services.

Last reviewed: 5 August 2026

Production security baseline

GT Connect combines application-level controls with the infrastructure, operational and governance controls applied across GTMaritime's certified AWS environment.

Tenant isolation and authorisation

Operational customer data is separated into PostgreSQL tenant schemas. Membership, role and permission checks protect workspace features and records at the application boundary.

Identity and provisioning protection

New workspaces require an administrator-issued, expiring, single-use invitation. Users set their own passwords and can enable authenticator-app MFA with high-entropy recovery codes. Workspaces can require MFA, and repeated failed sign-ins lock the account.

Session and abuse protection

Session duration is configurable within a secure maximum. Login, password-reset, MFA, workspace-provisioning and public action endpoints use account or IP-based throttling, as appropriate.

Browser and message security

GT Connect enforces HTTPS, secure cookies and a restrictive Content Security Policy. Attachment access is authenticated and inbound email HTML is sanitised before display.

Production infrastructure and storage

Production workloads run in GTMaritime's certified AWS environment using scoped workload permissions. Files and raw inbound email use private, encrypted storage with public access blocked.

Inbound email protection

Inbound email is withheld from processing until Amazon GuardDuty malware scanning reports it as clean. Unsafe or inconclusive items are quarantined for investigation.

Auditability

Immutable audit records cover identity, membership and role changes, workspace provisioning, feature configuration and important operational activity.

Operational monitoring and recovery

Worker heartbeats, inbound-email quarantine and processing issues, and external email delivery feedback are monitored. Durable receipts and replayable background processing support investigation and recovery.

ISO 27001 assurance

GT Connect and its production AWS environment are within the scope of GTMaritime's information security management system and covered by GTMaritime's ISO/IEC 27001:2022 certification. The certification applies to GTMaritime's management system and certified organisational scope rather than to an individual software product. Certificate and scope information can be provided during customer due diligence.

Continuous assurance

  • Risk assessment, supplier oversight and control review through GTMaritime's management system.
  • Automated dependency vulnerability checks and static application security analysis.
  • Product-specific incident, recovery and restoration exercises.
  • Documented recovery objectives, backup and retention controls.
  • Periodic independent application security testing.

Report a security concern

Please report suspected vulnerabilities or security incidents privately to infosec@gtmaritime.com. Do not include customer data beyond what is necessary to explain the issue.