Platform & security

Trust, built into the foundations.

A charter marketplace only works if every side can rely on the referee. That is why Yarentra's guarantees are not policies written in a PDF — they are rules enforced by the system itself, on every single request.

Three worlds, strictly separated

Sales partners, yacht operators and the charter team each work in their own portal with their own logins. These are not three views of the same data — they are three separate identity systems. A partner account cannot even formulate a request that would reach operator data, and vice versa.

Enforced in the database, not the interface

Access rules live in the database itself (row-level security): every record carries who may see it, and the database refuses everything else — regardless of what any screen, script or API would ask. Hiding a button is cosmetics; this is a locked door.

Non-circumvention by architecture

Partners never learn which operator runs a yacht; operators never learn which partner or client is asking. Prices for partners and rates for operators are calculated server-side per organisation. What is not transmitted cannot be misused — the anti-circumvention clause in the contracts is mirrored one-to-one in the data flow.

Everything leaves a trace

Registrations, releases, price changes, availability edits, document downloads, every sign-in: the audit log records who did what and when, with the old and new values. Disputes end quickly when the history is a fact, not a memory.

Money, treated like money

Eight currencies, VAT-aware line items, decimal-exact arithmetic — never floating-point. Each booking permanently stores its own commission calculation, so a rule change tomorrow can never rewrite what you earned yesterday. Customer invoices carry stable, sequential numbers.

Documents that carry your name

Quotations, booking confirmations and invoices are generated from the booking in one click — with the company logo, bank details, payment terms and a clean VAT breakdown. White-label by default, consistent every time.

Tested like it matters

The separation rules are covered by an automated security test suite that tries to break them on every change — cross-partner access, forged identities, operator reads of client data, price tampering. A release only ships when every one of those attacks fails.

Questions about the architecture?

We are happy to walk security-minded partners and operators through the details.