Product Security & Disclosure
Vulnerability reporting, security-update support period, and device data privacy
YACHTWAVE publishes a vulnerability disclosure policy, a defined five-year security-update support period, and a device data and privacy notice for YachtLINK™ (model YLK-1-WIFI). Security issues can be reported to [email protected].
Product Security
YACHTWAVE provides security updates for the YachtLINK™ YLK-1-WIFI for a defined support period of five (5) years from the date of first retail sale of the unit. Updates are delivered automatically over the air when the device is online; no user action is required.
Reporting a Security Vulnerability
If you believe you have found a security vulnerability in a YACHTWAVE product or service, please report it to [email protected]. Include the product model, firmware version if known, and enough detail to reproduce the issue. We will acknowledge your report within 5 business days, keep you informed of progress, and will not take legal action against good-faith security research. Please do not publicly disclose an issue before we have had a reasonable opportunity to address it.
Device Data & Privacy
The YachtLINK™ gateway reads vessel data from the NMEA 2000® network, which can include vessel position and voyage data. This data is:
- In transit: sent to the YachtWave cloud exclusively over encrypted HTTPS (TLS) connections.
- At rest on the device: buffered on internal memory and, where fitted, an internal microSD card encrypted with AES-256; the encryption key is unique per device, never leaves the device, and a card removed from the unit cannot be read.
- In your control: accessible only through your authenticated YachtWave account. A factory reset (5-second button hold) permanently erases all vessel data, Wi-Fi credentials, and cloud tokens from the device, including cryptographic erasure of the storage card.
- Retained: vessel telemetry is retained in the YachtWave cloud for 12 months, after which it is automatically deleted. Deleting your account removes all associated vessel data.
To request deletion of your account and associated vessel data, contact [email protected].
Device Credentials
YachtLINK™ does not use a universal default password. Each unit ships with a password that is unique to that device and printed on its durable label; it is not derivable from public information such as a serial number or MAC address. The credential is set at the factory, is not user-settable, and is retained across a factory reset, so the label remains accurate for the life of the product.
The device's own Wi-Fi access point is protected by that per-unit password, and the device's configuration pages answer only on that network — never over the vessel's or the marina's network.
Summary
| Security contact | [email protected] — acknowledgement within 5 business days |
|---|---|
| Minimum support period | Five (5) years from the date of first retail sale of the unit |
| Update delivery | Automatically over the air when the device is online, over HTTPS with integrity verification before installation |
| Device password | Unique per device, printed on the unit's label, not user-settable |
| In transit | Encrypted HTTPS (TLS), authenticated to the YACHTWAVE servers |
| At rest on the device | AES-256; key generated in the device, unique to that unit, never leaves it |
| Erasure | Factory reset (5-second button hold) destroys the key — data already written, including on a removed card, becomes permanently unreadable |
| Cloud retention | Vessel telemetry retained for 12 months, then automatically deleted |
This defined support period is the statement referenced by our UK PSTI Statement of Compliance and Australian RCM compliance page.