Application security review
Assess authentication, authorisation, data storage, network exposure, update mechanisms and relevant mobile or desktop application behaviour.
↗VIGILIS MARITIME RESEARCH LAB
Independent assessment for companies developing maritime software and connected products—including applications that exchange data with NMEA 2000 devices.
FOR MARITIME DEVELOPERS
Maritime applications often sit between mobile devices, onboard networks, gateways, cloud services and marine electronics. Security and resilience depend on how those boundaries are handled in real conditions.
Our laboratory creates controlled, repeatable scenarios around the application and the interfaces in scope. We help development teams uncover unsafe assumptions, weak data handling and integration problems before they reach a customer’s vessel.
LABORATORY SCOPE
Assess authentication, authorisation, data storage, network exposure, update mechanisms and relevant mobile or desktop application behaviour.
↗Evaluate how an application or gateway receives, interprets and transmits selected NMEA 2000 messages in a controlled test network.
↗Observe how the product handles missing, stale, conflicting, out-of-range or unexpected inputs, within an agreed safe test plan.
↗Assess behaviour during connection loss, device restarts, degraded data quality and recovery from interrupted sessions.
↗Create representative telemetry and validate product-specific alerts for suspicious endpoint, network or navigation-data behaviour.
↗Review trust boundaries between the app, vessel network, marine gateway, cloud components and the people who administer them.
↗NMEA 2000, CLEARLY DEFINED
NMEA 2000 is a marine data network used by compatible onboard instruments and systems. It carries standardised messages—known as Parameter Group Numbers, or PGNs—over a CAN-based network.
Our work focuses on the application, gateway and data behaviour that can be reproduced safely in the agreed test environment. Manipulating NMEA 2000 data in a lab is different from over-the-air GNSS interference, and the findings are described accordingly.
We can work before release, during integration, after a reported issue or as an independent security review for a customer or partner requirement.
A REPEATABLE ENGAGEMENT
Product version, components, interfaces, supported devices, test data and explicit boundaries.
Record expected behaviour and the evidence needed to interpret each scenario.
Execute controlled tests and preserve results so relevant findings can be reproduced.
Report impact, evidence, limitations and practical recommendations to the development team.