Security you can
take to the wellsite.
Drilling data is commercially sensitive and operationally critical. Greenstone is built with security as a first principle — not an afterthought — so operators can trust us with their most valuable subsurface data.
Security Controls
A layered defence across infrastructure, data, identity, and operations.
Data Encryption
- TLS 1.3 for all data in transit — no downgrade permitted
- AES-256 encryption at rest for all stored well data
- End-to-end encryption for wellsite-to-cloud WITSML streams
- Encryption keys managed via Cloudflare Key Management — never exposed to application code
Access Control
- Zero Trust architecture via Cloudflare Access — no VPN required
- Role-based access control (RBAC) at the well, project, and data level
- Multi-factor authentication enforced for all production access
- Short-lived API tokens — 1-hour expiry, automatically rotated
- Audit log for all data access events, exportable for compliance
Network Security
- Cloudflare WAF with OWASP ruleset — SQLi, XSS, RCE blocked at edge
- DDoS protection — L3/L4/L7 mitigated automatically
- Bot management — prevents scraping and credential stuffing
- IP allowlisting available for operator wellsite connections
- All traffic routed through Cloudflare Anycast network
Data Residency & Privacy
- UK/EU data residency options — operator data stays in-region
- GDPR compliant — data processing agreements available on request
- No training on operator data without explicit written consent
- Data deletion within 30 days of contract termination
- Sub-processor list published and maintained
Operational Security
- Infrastructure as Code — all changes peer-reviewed and auditable
- Dependency scanning on every commit via GitHub Actions
- Secrets managed in Cloudflare environment — never in code or logs
- Automated vulnerability alerts with 48-hour critical patch SLA
- Quarterly internal security reviews
Availability & Resilience
- 99.9% uptime SLA — backed by Cloudflare's global network
- No single region dependency — Anycast routing provides automatic failover
- Stateless compute (Workers) — horizontal scale without warm-up
- Read replicas for well data — zero downtime for analytics queries
- Incident communication via status page within 15 minutes
Compliance Status
Our current posture and roadmap — updated Q2 2026.
UK/EU data processing agreements available
Controls mapped, formal certification in roadmap
Audit scope defined — targeting Q4 2026
UK government scheme — assessment underway
Found a vulnerability?
We take security reports seriously. If you discover a vulnerability in any Greenstone product or infrastructure, please report it directly to our security team. We commit to acknowledging reports within 48 hours and providing a fix timeline within 5 business days for critical issues.
security@greenstone.energyWe do not pursue legal action against good-faith security researchers.