Security at Petronyx

Fuel stock, cash and staff records are some of the most sensitive data a business keeps. Here is how Petronyx protects them, layer by layer.

Six layers, all switched on.

Every item below is part of the shipped product, not a roadmap.

Identity

Who can get in, and how sure we are it is them.

  • Two-factor sign-in with an authenticator app
  • One-time recovery codes for a lost phone
  • Sign-in attempts are rate limited
  • Staff join by expiring email invitation, never shared passwords

Isolation

One company's records never sit beside another's.

  • A separate database schema for every company
  • Every request is scoped to the signed-in workspace
  • Encrypted connections from the app to the database

Access

People see what their role needs, at the stations they work.

  • Owner, admin, manager and operator roles
  • Station-level assignment for every staff member
  • Device sessions you can revoke one by one or all at once

Accountability

Sensitive actions leave a trail you can review.

  • Audit log of security and operational events
  • Retention from 90 days to 10 years by plan
  • Price changes and approvals keep their full history

Devices

Phones on a forecourt get borrowed, dropped and lost.

  • Biometric app lock
  • Tokens kept in the device's secure storage
  • Remote session revoke from the web

Application

Defaults that block whole classes of attacks.

  • Strict input validation that rejects unknown fields
  • Hardened HTTP security headers
  • Automated checks on every change before release

Found a vulnerability? Tell us first.

We welcome responsible disclosure. Write to security@petronyx.net and a member of the engineering team will reply.

How to report

  1. Email a description, the steps to reproduce and the impact you observed.
  2. Only test against your own account or workspace.
  3. Do not access, change or keep data that is not yours.
  4. Do not run denial-of-service, spam or social engineering tests.
  5. Give us reasonable time to fix the issue before sharing details.

These rules extend our Acceptable Use Policy.

Need a security review for procurement?

Request our security overview, signed data processing agreement or a completed questionnaire from the trust center.