Product Security & Disclosure

Vulnerability reporting, security-update support period, and device data privacy

← Back to Product Compliance

YACHTWAVE publishes a vulnerability disclosure policy, a defined five-year security-update support period, and a device data and privacy notice for YachtLINK™ (model YLK-1-WIFI). Security issues can be reported to [email protected].

Product Security

YACHTWAVE provides security updates for the YachtLINK™ YLK-1-WIFI for a defined support period of five (5) years from the date of first retail sale of the unit. Updates are delivered automatically over the air when the device is online; no user action is required.

Reporting a Security Vulnerability

If you believe you have found a security vulnerability in a YACHTWAVE product or service, please report it to [email protected]. Include the product model, firmware version if known, and enough detail to reproduce the issue. We will acknowledge your report within 5 business days, keep you informed of progress, and will not take legal action against good-faith security research. Please do not publicly disclose an issue before we have had a reasonable opportunity to address it.

Device Data & Privacy

The YachtLINK™ gateway reads vessel data from the NMEA 2000® network, which can include vessel position and voyage data. This data is:

To request deletion of your account and associated vessel data, contact [email protected].

Device Credentials

YachtLINK™ does not use a universal default password. Each unit ships with a password that is unique to that device and printed on its durable label; it is not derivable from public information such as a serial number or MAC address. The credential is set at the factory, is not user-settable, and is retained across a factory reset, so the label remains accurate for the life of the product.

The device's own Wi-Fi access point is protected by that per-unit password, and the device's configuration pages answer only on that network — never over the vessel's or the marina's network.

Summary

Security contact[email protected] — acknowledgement within 5 business days
Minimum support periodFive (5) years from the date of first retail sale of the unit
Update deliveryAutomatically over the air when the device is online, over HTTPS with integrity verification before installation
Device passwordUnique per device, printed on the unit's label, not user-settable
In transitEncrypted HTTPS (TLS), authenticated to the YACHTWAVE servers
At rest on the deviceAES-256; key generated in the device, unique to that unit, never leaves it
ErasureFactory reset (5-second button hold) destroys the key — data already written, including on a removed card, becomes permanently unreadable
Cloud retentionVessel telemetry retained for 12 months, then automatically deleted

This defined support period is the statement referenced by our UK PSTI Statement of Compliance and Australian RCM compliance page.