Security
Data Protection
Encryption, backups, and privacy practices
Protecting your well data and production information is fundamental to how we operate PetroBench.
Encryption
All customer data is encrypted both in transit and at rest:
| State | Method |
|---|---|
| In Transit | TLS 1.2+ encryption on all connections |
| At Rest | AES-256 encryption via AWS managed keys |
| Backups | AES-256 encryption, same standard as primary data |
| Database | Encrypted at the storage layer using AWS RDS encryption |
Data Isolation
Customer data is logically isolated between organizations:
- Each organization's data is segregated at the database level
- Access controls prevent cross-organization data access
- API authentication ensures requests only access authorized data
- Tenant isolation is enforced at the application and database layers
Backups
| Aspect | Details |
|---|---|
| Frequency | Daily automated backups |
| Type | Full snapshots with point-in-time recovery capability |
| Retention | 30 days |
| Encryption | AES-256 |
Data Retention
Customer data is retained for the duration of the service agreement. Upon account termination or a written deletion request, data is deleted within 30 days, including purging from backup rotation. Audit logs are retained for one year. Customers may request a data export at any time before account termination.
Privacy
What We Collect
PetroBench collects data necessary to provide the service:
- Well Data: Information you enter about wells, equipment, and configurations
- Simulation Data: Inputs, parameters, and results from RodSim simulations
- Account Information: User profiles, authentication credentials, organization details
- Usage Data: Platform interaction data for improving the service (anonymized)
How We Use Your Data
- Your well data and simulation results are used solely to provide PetroBench services
- We do not sell, share, or monetize customer data
Your Rights
- Export: Request a full copy of your data at any time
- Deletion: Request deletion of your data
- Correction: Update or correct your information through the platform
- Portability: Data exports provided in standard formats (CSV, JSON)
For privacy inquiries, contact legal@petrobench.com.