Security Statement

Last updated: July 2026 · FuelIQ Technologies Ltd.

Security is foundational to FuelIQ.

We protect fleet telemetry data, fuel transaction records, and customer account information using defense-in-depth security practices aligned with ISO 27001, SOC2 Type II, and GDPR requirements.

1. Infrastructure Security

  • Cloud Provider: Microsoft Azure (primary) and AWS (secondary) with multi-region deployment.
  • Data Encryption: AES-256 encryption at rest; TLS 1.3 for all data in transit.
  • Network Security: Virtual network isolation, DDoS protection, and Web Application Firewall (WAF) on all public endpoints.
  • Access Control: Azure Entra ID with RBAC, multi-factor authentication (MFA), and least-privilege principles.
  • Secrets Management: Azure Key Vault for API keys, certificates, and connection strings. No secrets in source code.

2. Application Security

  • Secure Development: OWASP Top 10 compliance, automated SAST/DAST scanning in CI/CD pipeline.
  • API Security: OAuth 2.0 authentication, rate limiting, input validation, and request signing for device-to-cloud communication.
  • Dependency Management: Automated vulnerability scanning of all third-party dependencies.
  • Penetration Testing: Annual third-party penetration testing with remediation tracked to completion.

3. Data Security

  • Encryption: All telemetry data encrypted before storage. Customer-managed encryption keys (CMEK) available for Enterprise plans.
  • Backup: Automated daily backups with geo-redundant replication. Recovery Point Objective (RPO): 1 hour. Recovery Time Objective (RTO): 4 hours.
  • Data Isolation: Enterprise customers receive dedicated Azure/AWS tenants with logical data isolation.
  • Audit Logging: Immutable audit logs for all data access, modifications, and administrative actions.

4. IoT Device Security

  • BLE Sensor Auth: Each probe uses unique device certificates for MQTT broker authentication.
  • Firmware Updates: Over-the-air (OTA) firmware updates signed with asymmetric key pairs.
  • Tamper Detection: Physical tamper events trigger immediate alert and device self-reporting.
  • Protocol Security: MQTT over TLS 1.3 with EMQX Enterprise broker authentication.

5. Compliance & Certifications

ISO 27001 Certified

Information Security Management System certified by accredited auditor.

SOC 2 Type II Ready

Controls for security, availability, and confidentiality audited annually.

GDPR Compliant

Data processing, storage, and transfer comply with EU General Data Protection Regulation.

NDPR Compliant

Nigeria Data Protection Regulation compliance for all Nigerian operations.

6. Incident Response

FuelIQ maintains a documented Incident Response Plan with defined escalation procedures. Security incidents are triaged within 1 hour of detection, with customer notification within 72 hours for incidents involving personal data. A dedicated security team monitors the platform 24/7.

7. Report a Vulnerability

We welcome responsible disclosure of security vulnerabilities. Please report security issues to security@fueliq.tech. We commit to acknowledging receipt within 24 hours and providing a remediation timeline within 7 business days.

8. Contact

Security Team: security@fueliq.tech
Data Protection Officer: dpo@fueliq.tech
FuelIQ Technologies Ltd., Lagos, Nigeria