What access do you actually need?
IT teams are right to scrutinize every external application introduced into a refinery environment. So when IT evaluates EZTRAK, the first question we want them to ask is what access we actually need.

IT teams are right to scrutinize every external application introduced into a refinery environment. The first question should be simple: what access does the vendor actually need?
EZTRAK can operate with no persistent system-to-system connection at all. Authorized users export approved data from the source system and import it into EZTRAK, which keeps the customer in control of what information crosses the boundary and when.
Where a customer wants automation, we can integrate — and we apply the same principle, limiting the interface to approved data flows rather than requiring broad access into customer systems. The level of access is a decision you make, not a condition of using the platform.
Separation from OT
EZTRAK does not connect to process control, safety instrumented systems, or other OT and control systems. It is not designed to communicate with them and does not require connectivity to your OT environment.
- No SAP or ERP credentials
- No service account in your environment
- No inbound firewall access
- No OT connectivity
Security controls that matter
- Contractor access. Granted through an approval request that specifies the duration up front. Access expires at the end of the approved period and requires a new request to renew.
- Role-based access. Permissions are scoped by role across the platform.
- Identity. SSO via SAML with your identity provider, and MFA.
- Tenancy. Dedicated customer environments are available where separation from a shared application environment is required.
- Encryption. Customer data is encrypted at rest and in transit.
- Audit trail. User transactions are attributed and timestamped — who did what, to which record, and when.
- Internal access. Production access is restricted by role and limited to authorized personnel with an operational need.
- Vulnerability management. Continuous automated vulnerability scanning.
- Backups. Performed daily.
- Hosting and residency. EZTRAK is hosted in Microsoft Azure in the United States, with production data hosted in U.S. environments.
- Mobile access. EZTRAK supports mobile and offline operation for field use, with role-based access controls applied to mobile users.
If something goes wrong
If a confirmed or suspected security incident affects customer data, we follow our incident-response process, notify designated customer contacts in accordance with applicable requirements, and provide updates as the investigation progresses.
Your data is yours
Customer data remains customer-owned and can be exported in standard formats. We do not believe data portability should be used as a commercial lever. If the relationship ends, we will support the required transition and data-export process.
Should you build it internally?
An internal build is a legitimate option, and for some organizations it will be the right one. The organization assumes the full application lifecycle — architecture, identity and access management, vulnerability management, patching, testing, infrastructure and long-term ownership.
A third-party platform should have to justify the access and risk it introduces. One of the first questions should be simple: what access does the vendor actually need?
We do not expect your IT team to trust a marketing claim about security. We expect them to examine the architecture, challenge the controls, and decide for themselves. We will give them what they need to do that.