Security for operating data
Wellsite is designed to bring private operating activity, authorized service providers, and AI agents into the same operating environment.
That requires clear boundaries around identity, access, authority, and auditability.
Access follows authorization
A person should not gain broad access to an operator’s wells simply because they have a Wellsite account.
Access is based on organization membership, role, resource scope, work authorization, capability, and expiration.
Outside service providers participate in private operations through operator-authorized work.
Agent authority is explicit
AI agents operate within authority defined by the operator.
- Watch.
- Recommend.
- Prepare.
- Execute.
Authority can vary by agent and by task.
Agents cannot exceed the authority established for them.
Consequential activity is auditable
Wellsite is designed so consequential operational actions can be attributed to the person, agent, or organization responsible for them.
The operating history should make it possible to understand what happened, when it happened, what object it affected, and what changed.
Private operations stay private
Public well identity and public regulatory information are separate from private operating data.
Private production details, economics, service relationships, projects, documents, and other operating records are governed by the permissions around the operator’s private Wellsite.
Security program
Documentation of the security program will cover:
- Authentication architecture
- Encryption practices
- Infrastructure and provider details
- Backup and disaster-recovery practices
- Vulnerability-management practices
- Security certifications or attestations, if any
No certifications, encryption standards, uptime guarantees, penetration-test cadence, or other security assurances are claimed here until verified.
A dedicated security contact will be published here.