Policies

Compliance

Certifications, frameworks, and regulatory compliance

PetroBench maintains security and compliance practices designed for enterprise oil and gas operators. This page provides transparency into our certifications and the frameworks that govern our security program.

Framework Alignment

PetroBench's security program is aligned with industry-standard frameworks:

FrameworkAlignment
NIST Cybersecurity Framework (CSF)Controls mapped to NIST CSF categories
OWASP Top 10Web application security testing covers all OWASP Top 10 categories

Security Assessments

AssessmentFrequency
Vulnerability ScanningContinuous automated scanning of infrastructure and dependencies
Static Analysis (SAST)Every code change, integrated into CI/CD pipeline
Dependency AuditingContinuous automated alerts for known vulnerabilities

Data Handling

PracticeDetails
Data ResidencyUnited States only (AWS US East, Virginia)
Data OwnershipCustomers retain full ownership of their data
Data PortabilityExport available in CSV and JSON formats
Data DeletionWithin 30 days of request or account termination
Data ClassificationWell data and simulation results classified as confidential; usage analytics anonymized

Request Documentation

To request compliance documentation, audit reports, or a Data Processing Agreement:

On this page