Policies

Policies

The written internal policies that govern how PetroBench builds and operates the platform

PetroBench maintains written internal policies covering security, data handling, operations, and personnel. They are reviewed monthly. Policy names link to the published detail where it exists.

Security

PolicyWhat it covers
Information SecurityInfrastructure, encryption, and network controls
Access ControlPermissions, authentication, and production access
Change ManagementHow changes are reviewed, tested, and released
Endpoint SecurityHardening of company devices
Secrets ManagementWhere credentials are held and how leaks are caught
Logging and AuditWhat activity is recorded and monitored
Vulnerability DisclosureHow vulnerabilities are reported and handled

Data

PolicyWhat it covers
Data Protection and RetentionStorage, residency, backups, export, and deletion
Data ClassificationHow customer data and analytics are classified
PrivacyCollection, use, and ownership of personal information
AI and Machine LearningUse of customer data in AI-assisted features
Subprocessor ManagementThird parties that process customer data

Operations

PolicyWhat it covers
Incident ResponseHandling and communication of security and availability incidents
Business ContinuityBackups, recovery, and continuity of service
Service AvailabilityUptime commitments, maintenance, and support response
Compliance and AssessmentFramework alignment and ongoing security testing
Risk ManagementHow security and reliability risks are tracked

People and Use

PolicyWhat it covers
Personnel SecurityScreening, training, and access for employees and contractors
Acceptable UsePermitted and prohibited use of the platform
Shared ResponsibilityWhat PetroBench secures and what the customer controls

Governance

Policies are owned by PetroBench leadership and reviewed monthly, and whenever our practices, infrastructure, or legal obligations change. Material changes to customer-facing policies are communicated by email.

On this page