
Security & Compliance
Your Data Security Is Our Priority
Barreleye is built to handle critical water management data for energy operations. Our platform is designed to ensure your data is secure, isolated, and always available when you need it.
SOC 2 Type II
Barreleye has maintained SOC 2 Type II compliance since 2024. An independent third-party auditor has verified that our systems and processes meet strict standards across the Trust Services Criteria.
As part of the audit, reviewers evaluated:
-
Software development and change management processes
-
Testing and deployment controls
-
Infrastructure design and security practices
This provides formal assurance that Barreleye operates with rigorously audited controls to protect customer data.
Trust Services Criteria Covered:
Our SOC 2 Type II report covers five key areas that ensure your data is handled with the highest standards of security and care.
-
Security: Protection against unauthorized access
-
Availability: Systems remain operational and accessible
-
Processing Integrity: Accurate and reliable data processing
-
Confidentiality: Protection of sensitive business data
-
Privacy: Responsible handling of personal information
Compliance documentation is available upon request. Contact us to learn more.
Identity & Access Management
Barreleye integrates with modern identity providers, including Microsoft Entra ID, enabling single sign-on (SSO) and centralized access control. Authentication is handled through industry-standard OIDC flows, eliminating the need for Barreleye-managed passwords.
Tenant Isolation
by Design
Each customer environment is logically isolated, with strict separation of data, services, and access boundaries. This ensures that customer data is never accessible across tenants and significantly reduces blast radius.
Encryption & Data Protection
All data is encrypted in transit (TLS) and at rest. Access to sensitive data is governed by role-based access controls and least-privilege principles. These protections apply across all environments and are enforced at every layer of the platform.
Monitoring
& Detection
We use centralized logging, monitoring, and alerting to detect and respond to potential issues quickly. This gives our team visibility across the platform so threats are identified and addressed before they become problems.
Controlled Changes
& Auditing
All changes to the system are tracked, reviewed, and tested prior to deployment. Access and infrastructure are regularly reviewed as part of our SOC 2 controls.

