Loading
WTI Crude$/bbl|Brent Crude$/bbl|Henry Hub Gas$/MMBtu|US Rig Countrigs|Canada Rigsrigs|Global LNG$/MMBtu|WTI Crude$/bbl|Brent Crude$/bbl|Henry Hub Gas$/MMBtu|US Rig Countrigs|Canada Rigsrigs|Global LNG$/MMBtu|
Trust & Security

Security you can
take to the wellsite.

Drilling data is commercially sensitive and operationally critical. Greenstone is built with security as a first principle — not an afterthought — so operators can trust us with their most valuable subsurface data.

Encryption
TLS 1.3 + AES-256
Auth
Zero Trust / MFA
Network
Cloudflare WAF
Privacy
GDPR Compliant

Security Controls

A layered defence across infrastructure, data, identity, and operations.

Data Encryption

  • TLS 1.3 for all data in transit — no downgrade permitted
  • AES-256 encryption at rest for all stored well data
  • End-to-end encryption for wellsite-to-cloud WITSML streams
  • Encryption keys managed via Cloudflare Key Management — never exposed to application code

Access Control

  • Zero Trust architecture via Cloudflare Access — no VPN required
  • Role-based access control (RBAC) at the well, project, and data level
  • Multi-factor authentication enforced for all production access
  • Short-lived API tokens — 1-hour expiry, automatically rotated
  • Audit log for all data access events, exportable for compliance

Network Security

  • Cloudflare WAF with OWASP ruleset — SQLi, XSS, RCE blocked at edge
  • DDoS protection — L3/L4/L7 mitigated automatically
  • Bot management — prevents scraping and credential stuffing
  • IP allowlisting available for operator wellsite connections
  • All traffic routed through Cloudflare Anycast network

Data Residency & Privacy

  • UK/EU data residency options — operator data stays in-region
  • GDPR compliant — data processing agreements available on request
  • No training on operator data without explicit written consent
  • Data deletion within 30 days of contract termination
  • Sub-processor list published and maintained

Operational Security

  • Infrastructure as Code — all changes peer-reviewed and auditable
  • Dependency scanning on every commit via GitHub Actions
  • Secrets managed in Cloudflare environment — never in code or logs
  • Automated vulnerability alerts with 48-hour critical patch SLA
  • Quarterly internal security reviews

Availability & Resilience

  • 99.9% uptime SLA — backed by Cloudflare's global network
  • No single region dependency — Anycast routing provides automatic failover
  • Stateless compute (Workers) — horizontal scale without warm-up
  • Read replicas for well data — zero downtime for analytics queries
  • Incident communication via status page within 15 minutes

Compliance Status

Our current posture and roadmap — updated Q2 2026.

GDPRCompliant

UK/EU data processing agreements available

ISO 27001Aligned

Controls mapped, formal certification in roadmap

SOC 2 Type IIRoadmap

Audit scope defined — targeting Q4 2026

Cyber EssentialsIn Progress

UK government scheme — assessment underway

Responsible Disclosure

Found a vulnerability?

We take security reports seriously. If you discover a vulnerability in any Greenstone product or infrastructure, please report it directly to our security team. We commit to acknowledging reports within 48 hours and providing a fix timeline within 5 business days for critical issues.

security@greenstone.energy

We do not pursue legal action against good-faith security researchers.