ACSS Blog — 2 October 2026

How secure is your fish processing software? What we check every quarter

What a security review of factory software should cover, what our latest review of Aquarius Pro found, and the questions to ask any software supplier.

The short answer: your factory software holds your orders, prices, customer lists and traceability records, so its security matters as much as the lock on the factory door. We review the security of Aquarius Pro every quarter: the code, its configuration, the third-party libraries it uses, and operational controls such as backups and encryption. Our latest review, dated 25 September 2026, found no critical or high-risk weaknesses in the application code. The one substantive finding, outdated third-party libraries, has been fixed, and you can download the full report.

What our quarterly security review of Aquarius Pro covers: code, configuration, third-party libraries and operations, with the results of the September 2026 review: no critical or high findings in the application code, 27 library issues fixed, and one open item to confirm the two-step login policy

Why does software security matter to a fish business?

Most of the fish businesses I talk to think about security in physical terms: who has keys, whether the chillers are alarmed. But a lot of what makes your business valuable now sits in software. Customer orders and prices, supplier details, stock, and the lot records you need when an inspector asks where a box came from.

Two things can go wrong. Someone could see data they shouldn't, such as a competitor's prices or your customer list. Or the system could stop working when you need it, at four in the morning with vans waiting to be loaded.

There is a legal side too. Customer and staff contact details are personal data under UK GDPR. If a breach of personal data is likely to put people at risk, you have to report it to the Information Commissioner's Office (ICO) without undue delay, and no later than 72 hours after becoming aware of it. If your software supplier suffers the breach, the law says they must tell you without undue delay, so you can meet that deadline.

What do we check every quarter?

Each quarter we review Aquarius Pro, our cloud system at app.acss.co.uk, in five areas:

  1. Architecture and hosting. How the system is deployed and which platform controls protect it.
  2. The source code, against the themes of the OWASP Top 10 and the OWASP Application Security Verification Standard (ASVS), the most widely used checklists for web application security. That covers logins and sessions, who can see what, keeping each customer's data separate, protection against injection attacks, input checking, data protection, and how passwords and keys are stored.
  3. Configuration. HTTPS everywhere, and the security headers that tell browsers what a page may and may not do.
  4. Third-party libraries. Like almost all modern software, Aquarius uses open-source building blocks. We check every one against published lists of known vulnerabilities, update what needs updating, and scan again.
  5. Operational controls. Backups, encryption, where data is stored, how secrets are held, and how we would respond to an incident.

To be clear about what this is: a manual and tool-assisted review of the code and configuration, carried out by our own team. It is not an independent penetration test, where an outside firm actively tries to break into the running system. The report says so on page two, along with what was out of scope.

What did the latest review find?

The review found no injection, login or access-control weaknesses in the application code. It rated the overall security position as strong. There were four findings in total:

Finding Severity Status
Third-party libraries with known vulnerabilities: 27 issues, 1 rated critical and 10 high, most of them ways to slow down or crash a process Medium Fixed
A browser-side library advisory that only applied to a mode Aquarius doesn't use Low Fixed
Nothing stopped a new release going out with a known-vulnerable library Informational Fixed
Confirm that two-step login (MFA) is enforced for staff and admin accounts, and state the position for customer users Informational Open

The first finding was the only substantive one, and the third explains how it happened. Automated update suggestions were in place, but nothing blocked a release if someone didn't act on them, so the backlog built up. Both are now closed: every flagged library is on a fixed version, and a check in our release process now refuses to ship any build that contains a library with a known high or critical issue.

The open item is about policy rather than code. Two-step login is already available. What remains is to confirm it is switched on for every ACSS staff and admin account, and to set out our position for customer users. It will be covered in the next review.

Where is your data, and how is it protected?

These are the controls the review confirmed:

  • Location. Aquarius runs on Google Cloud in the London region. Backups are kept in the EU. Google's own data centres are covered by its certifications, including ISO/IEC 27001.
  • Encryption. Data is encrypted in transit and at rest, in the databases and in file storage.
  • Backups. Automatic daily backups, kept for seven days, with point-in-time recovery across that window, so we can restore to a moment before a problem rather than just last night.
  • Keeping customers apart. Each business's data is separated inside the database itself, not only in the application. The system refuses to start if that separation could be bypassed, and since this review, automated tests check on every release that one customer can't see another's data.
  • Logins and sessions. Passwords are stored as one-way hashes, never in readable form, and idle sessions are logged out after eight hours.
  • Secrets. No passwords or keys in the source code. They are held in Google Secret Manager.
  • Incidents and your rights. We have a written incident response process that follows UK GDPR timelines. A data protection pack and a template data processing agreement are available on request.

We also tightened two things during this review. Recordings of phoned-in orders and attachments on support tickets are now served through short-lived links that only work for the business they belong to.

What should you ask any software supplier?

Whether you use Aquarius or not, these questions are worth putting to anyone who holds your data. The National Cyber Security Centre (NCSC) publishes 14 cloud security principles that go into more depth, and they are a good reference if a supplier's answers are vague.

Ask Why it matters
Where is my data stored, and is it encrypted? You need to know which country it's in for UK GDPR, and that a lost disk or backup can't be read.
How often do you back up, and how far back can you restore? A daily backup is only useful if it can actually be restored, quickly.
How do you keep my data separate from other customers'? On shared cloud systems this is the control that matters most.
When did you last review security, and can I see the result? Anyone can say "secure". A dated report with findings and fixes is evidence.
Can we turn on two-step login? It keeps criminals out of an account even if they know the password.
Will you sign a data processing agreement? UK GDPR sets out what your contract with a processor must cover, including the security measures they have to take.
How quickly will you tell us about a breach? You have 72 hours to report a notifiable breach to the ICO, and the clock starts when you become aware of it.

A supplier that answers these clearly, in writing, is taking the subject seriously. One that can't find the answers probably hasn't asked itself the questions.

How does Aquarius handle this?

Aquarius Pro is our cloud system for fish and seafood processors, packers and merchants. The quarterly review is how we hold ourselves to the standard above, and we publish the result so you don't have to take our word for it. The latest report is eight pages and covers the methodology, every finding and every control. If your insurer, auditor or a major customer asks about your software's security, it's yours to share. If you have questions about it, or need our data processing agreement, get in touch.

Quick answers

How often do you review Aquarius security? Every quarter. Each review covers the code, its configuration, third-party libraries and operational controls, and ends with a written report.

Is it a penetration test? No. It is a code and configuration review by our own team. It doesn't replace a penetration test, where outside testers attack the live system, and the report says so.

Where is Aquarius data stored? On Google Cloud in the London region, encrypted in transit and at rest. Backups are kept in the EU.

What happens if something goes wrong? We have a written incident response process that follows UK GDPR timelines, and daily backups with point-in-time recovery for seven days.

Can I see the report? Yes, the full report is free to download.

This is a practical summary, not legal advice. For your own UK GDPR obligations, see the ICO's guidance or speak to an adviser.

Sources

← All posts

Contact us for more details, questions or additional information