SECURITY
Straight answers about how your data is protected.
Your tank levels, delivery records, and site details are business information. Here is what protects them, in plain terms — including what still depends on how your deployment is set up.
SECURITY SUMMARY
Last reviewed July 28, 2026
THE QUESTIONS THAT MATTER
Six questions we get from IT and procurement — answered.
No badge wall, no buzzwords. If your review needs more depth than this page, we will walk your team through the architecture directly.
01
Who can get in?
Nobody sees your data without an account you created. Every page and every connection requires sign-in, passwords are never stored in readable form, and repeated failed sign-in attempts are slowed automatically.
02
Can staff see only their own sites?
Yes. Administrators, owners, and operators have separate permissions, and any user can be limited to specific locations. A driver in one region never sees another region's tanks.
03
What about saved equipment passwords?
Passwords for connected systems — gauges, integrations, backup storage — are stored encrypted and are never sent back to a web browser. Once saved, they cannot be read out again, even by your own administrators.
04
How does tank data travel?
Your browser reaches GaugeLink over HTTPS, the same encryption standard used for online banking. DTU gateways report in through an encrypted private tunnel. If you choose a direct firewall connection instead, we help you restrict it so only GaugeLink can reach the gauge.
05
What happens if something fails?
Backups cover the database and your documents, on a schedule you control. A copy can be kept off-site on your own storage, and restoring follows a guarded, step-by-step process — not improvisation.
06
Where can it be reached from?
The databases behind GaugeLink are never exposed to the internet. You can also restrict sign-ins by country or region, so the portal is reachable only from the places you actually operate.
HONESTY OVER BADGES
What we deliberately do not claim.
Vendors that promise everything protect nothing. Knowing where our responsibility ends is part of trusting what we do promise.
We do not display certification badges we have not earned. If your procurement process needs a specific attestation, ask — we will tell you exactly where we stand.
The encrypted gateway tunnel protects readings on their way in. It does not make every email, export, or browser tab “end-to-end encrypted”, and we will not pretend it does.
Security is shared. We secure the application; hosting choices, secret handling, and update practice are agreed as part of your deployment plan.
Off-site backups are encrypted while they transfer. Encrypting the storage they land on is a choice made in your environment, and we will help you make it.
This page stays useful to attackers-in-training at exactly zero: no hostnames, ports, or internal details are published here.
START A CONVERSATION
Put us in front of your IT and procurement team.
We would rather answer the hard questions before you commit than after. A security review covers the architecture, the access model, how data flows, and exactly who is responsible for what.
