Manifest (“Manifest”, “the platform”) is a secure platform for managing the marine protection & indemnity (P&I) renewal book. The platform is owned and operated by Enkefalos Holdings Ltd (“we”, “us”, “our”). This policy explains what we process, how it is protected, and the rights you have. It applies to people authorised to use Manifest; it is not a consumer service.
Zero-knowledge by design
Manifest is zero-knowledge: your business data is encrypted in your browser before it is sent anywhere. The encryption keys are derived from your personal Manifest Key and never leave your device. As a result, the servers — and therefore we and our providers — only ever hold ciphertext and cannot read your renewal data.
Who controls your data
The data you put into Manifest belongs to your organisation, not to us. We act as a processor of that data on your organisation's behalf and only on its instructions. We do not own, sell, rent, or share the data you provide, and we do not use it for any purpose other than operating the platform for you.
We do, however, own the platform itself and any anonymised and aggregated derivations, statistics, predictions, and models that we create from data processed on the platform — provided these do not identify you, any individual, or any organisation, and cannot reasonably be used to reconstruct the original data. These derivations are used to operate, secure, and improve Manifest.
What we process
- Account identity: your work email address, used to sign you in (passwordless magic link) and to apply your role.
- Encrypted records: the renewal data you enter or import, stored only as ciphertext plus the cryptographic wrapping metadata needed to unlock it on your device.
- Minimal technical data: an essential authentication session cookie and basic security/operational logs (e.g. request metadata). We do not use advertising or tracking cookies and do not profile you.
How we use it
Solely to provide and secure the platform — to authenticate you, enforce access controls, operate the service, and produce the anonymised, aggregated derivations described above. We do not sell data, serve advertising, or use it for any purpose unrelated to running Manifest.
Service providers
We use a small number of processors under their respective data-processing terms, and they receive only the minimum required:
- Supabase — authentication and encrypted (ciphertext) storage.
- Resend — delivery of transactional sign-in emails.
- Vercel — application hosting and content delivery.
Security
Data is protected with industry-standard cryptography — AES-256-GCM record encryption, RSA-OAEP key sharing, and a memory-hard Argon2id key derivation — plus database row-level security, encryption in transit (HTTPS/HSTS), a strict content-security policy, and an idle auto-lock. Please note that because only you hold your Manifest Key, if it is lost your data may be unrecoverable (an organisation-level break-glass key exists for emergency recovery).
Retention
Encrypted records are retained for as long as the renewal book is in use, or as your organisation's records policies require, and remain encrypted throughout. Account records are removed when access is revoked, subject to legal retention duties.
Your rights & contact
You can view and correct your data directly in the app. For any other request, or questions about this policy, contact your Manifest administrator, who will route it to the operator. Where applicable law grants additional rights (e.g. UK GDPR), we will honour them. Enkefalos Holdings Ltd is the operator responsible for this platform.
Changes
We may update this policy; material changes will be posted here with a new “last updated” date.
