Security

Security for operating data

Wellsite brings private operating activity, authorized service providers, and AI agents into the same operating environment.

That requires clear boundaries around identity, access, authority, and auditability — enforced by the system, not by policy.

Access follows authorization

A person does not gain broad access to an operator’s wells simply because they have a Wellsite account.

Access is based on organization membership, role, resource scope, work authorization, capability, and expiration.

Agent authority is explicit

AI agents operate within authority defined by the operator.

  • Watch.
  • Recommend.
  • Prepare.
  • Execute.

Agents cannot exceed the authority established for them.

Consequential activity is auditable

Every consequential operational action is attributed to the person, agent, or organization responsible for it, in an append-only log.

Private operations stay private

Public well identity and public regulatory data are separate from private operating data, which is governed by the permissions around the operator’s private Wellsite.

Security program

How Wellsite is secured

What follows is what the system enforces today, category by category. Nothing here is a promise about the future.

Identity

Every person signs in with a one-time code to their email or verified mobile number. There are no passwords to leak or reuse.

Every operator organization is created with a company email and a card on file. The card is not charged; it is the identity check that keeps anonymous accounts off the platform.

Mobile numbers and email addresses change only through a verification code.

Tenant isolation

Row-level security is on and forced for every table in the platform database. The service that answers requests cannot bypass it.

Every request runs inside one organization’s context. Every AI agent runs as a principal of exactly one organization, pinned to that organization’s credential. A prompt-injection attempt gets the same answer as any other unauthorized request: nothing.

Access follows authorization

Access is based on organization membership, role, resource scope, work authorization, capability, and expiration.

A service provider’s access is a grant scoped to the job — the wells, the project, the capabilities it needs — and ends when the job does. A regular pumper holds a standing grant to a route and nothing more. Provider accounts are invitation only.

Agent authority is explicit

AI agents operate within authority defined by the operator.

  • Watch.
  • Recommend.
  • Prepare.
  • Execute.

Out of the box every agent watches and drafts. Anything that can spend carries a per-action ceiling. Guardrails live in one place, changeable only by an organization admin. Five things never move automatically at any setting: signing or submitting a filing, moving money, granting standing access, committing above a ceiling, and making an offer on an asset.

Auditability

Every consequential action is written to an append-only activity log, attributed to the person, agent, or organization responsible, in the same transaction as the change itself. Corrections supersede earlier entries; nothing is edited in place.

Every agent evaluation is logged too — what it saw, concluded, ruled out, and did, including the wells where it raised nothing.

Data ownership and privacy

The operator owns its operating data. Service providers own the history of their own work. Public well identity and public regulatory data are kept separate from private operating data.

Agents learn from your own operating history and from public data, never from another customer’s operation. Customer operating data is not used to train AI models.

Infrastructure and payments

Wellsite runs on Amazon Web Services in the United States. Every connection is encrypted in transit. Credentials and keys live in AWS-managed secret storage, never in code.

Card details never touch Wellsite. Stripe holds them; Wellsite stores only a customer reference and the subscription state.

Vulnerability disclosure

If you believe you have found a security issue, tell us through the contact form and choose Security as the topic. Reports reach the people who can act on them directly, and we will acknowledge what we receive.

Wellsite claims no certification, attestation, uptime guarantee, or penetration-test cadence it has not completed.

Put an AI agent team on every well.