Drilliumby Petromium
Back to Drillium
Commercial data governance

Data processing overview

This overview supports diligence. An executed data-processing agreement, regional schedule and subprocessor list will control where required after legal review.

Organization and Petromium roles

The subscribing organization determines the purpose and authorized content of its engineering workspace. Petromium processes that information to provide, secure, support, back up and audit Drillium. Petromium acts independently for its own account security, billing, fraud prevention and legal obligations.

Subprocessors

Infrastructure providers host the application, PostgreSQL, controlled documents, backups, monitoring and malware scanning. Stripe processes hosted billing and payment information. Resend processes transactional email. Provider region, transfer mechanism and notice commitments will be stated in the executed schedule.

Security and assistance

Drillium uses organization scope, role authorization, mandatory authenticator setup, encryption in transit, deployment-managed secrets, controlled uploads, audit logs, backups and recovery tests. Petromium will define incident, data-subject, audit and deletion assistance in the executed agreement. This is not a claim of independent certification.

Request an agreement

Commercial operators may request the current DPA, security schedule and subprocessor register from privacy@petromium.com.

Effective 23 July 2026 · Version drillium-processing-2026-07-v1 · Pending legal review