Fuel island controllers
Authorization rules, pump enable and transaction capture read straight off the controller.
Reservo brings fuel inventory, dispensing authorization, transactions, alarms and compliance reporting into one cloud console. It talks to the island controllers, tank gauges and dispensers already in the ground, so nothing has to come out.
Reservo connects to the fuel equipment you already own, using native protocols wherever they exist and keeping third-party middleware out of the path. Dispensers, gauges and field equipment stay where they are.

A forecourt already produces every number Reservo needs. The equipment is not the problem, the fact that the data stops at the site is.
Authorization rules, pump enable and transaction capture read straight off the controller.
Product level, water level, temperature and ullage polled on a schedule you set.
Pump status, meter totals and per-hose volumes tied back to each transaction.
Cardholder, vehicle and driver identification carried through to the audit record.
Existing site logic stays intact. Reservo reads from it rather than replacing it.

Every hose, meter and reader at the island already produces the data you need. The gap is that it stops at the site. Reservo reads those outputs at source and carries them to one record, rather than stacking another translation layer on top of equipment that is working fine.

Each hose is mapped to a grade and a tank, so a transaction knows which product actually moved.

Card, PIN and grade selection identify the cardholder, the vehicle and the product before the pump enables.

Meter totals per hose reconcile against the tank gauge, which is where shrinkage shows up first.
Scope note: replacement of physical fuel dispensers, tank gauges or other field equipment is not included unless separately contracted.
The dashboard is built from widgets your users arrange themselves. A regional manager watches consumption and delivery variance. A site manager watches tank levels and open alarms. Same data, different desks.
Group facilities by region, contract, division or however your organization is actually structured. Roll numbers up, drill numbers down, and give each site manager exactly the sites they are responsible for.


Facilities can be grouped by region, contract or division. The rollup follows your org chart rather than the vendor's.
| Site | Group | Tanks | On hand | Gateway | Last sync | Alarms |
|---|---|---|---|---|---|---|
| 04 · North Yard | Midwest | 4 | 24,094 gal | Online | 12s | 1 low |
| 07 · River Depot | Midwest | 3 | 18,760 gal | Online | 8s | 1 leak |
| 11 · Airfield East | Southeast | 2 | 31,402 gal | Buffering | 41m | Clear |
| 02 · Central Garage | Midwest | 3 | 15,880 gal | Online | 6s | Clear |
| 19 · Transit Barn | Northwest | 5 | 40,118 gal | Online | 15s | Clear |
Site 11 is running on cellular backup and buffering locally. Nothing is lost. Records sync in order once the primary link returns.
A small edge gateway sits between your field equipment and the cloud. It speaks the hardware's protocol, buffers everything locally, and pushes to the platform over an encrypted channel. Losing connectivity is an inconvenience, not a data gap.
Primary connectivity uses the network you already run at the site, with cellular available as backup and automatic failover between them.
During an outage the gateway keeps recording transactions, gauge readings and audit events to local storage in full detail.
When the link returns, buffered records upload in sequence and reconcile against the cloud. No one has to press anything.

A gateway is not signed off because it powered on. Each one is checked against the physical gauge and a metered draw at the pump, so the first number you see in the console is a number you can defend. Sites go live one at a time, on a sequence agreed in the deployment schedule.
Reservo covers the full loop: who is allowed to draw fuel, what actually came out of the tank, what was delivered back in, and whether those three numbers agree.

The record starts the moment the nozzle leaves the boot and closes when the meter stops.
| Date and time | 2026-08-06 09:41:22 |
| Site | 04 · North Yard |
| Pump / hose | Pump 3 · Hose A |
| Product | Diesel · Tank T1 |
| Vehicle | Unit 118 · Odo 84,302 |
| Driver | D-2209 · Verified |
| Authentication | Card 6612 · PIN |
| Quantity | 42.6 gal |
Every transaction keeps its full field set for the life of the record, searchable and exportable without a support ticket.

A delivery is logged against the tank it filled, the gauge reading before and after, and the quantity on the bill of lading. Reservo flags the variance instead of waiting for someone to notice it in a spreadsheet three weeks later.
Reservo watches inventory, equipment and behaviour continuously, and raises the ones that matter through the channel that will actually reach the person on shift.

Whoever holds the shift gets the notification on whatever they are carrying. Acknowledgement is captured with the user and the time, so an alarm that went quiet has a name attached to why.
Logins, administrative actions, inventory adjustments, configuration changes, permission updates and alarm acknowledgements are written to an append-only record. Every entry carries the before value and the after value.
| Timestamp | User | Action | Previous | Updated | Site |
|---|---|---|---|---|---|
| 2026-08-06 09:12:04 | m.okonkwo | Inventory adjustment · T3 | 2,240 gal | 2,180 gal | 04 |
| 2026-08-06 08:47:51 | system | Gateway state change | Online | Buffering | 11 |
| 2026-08-06 08:20:19 | r.delacruz | Role assignment | Operator | Site Manager | 02 |
| 2026-08-06 07:30:02 | j.whitfield | Alarm acknowledged | Open | Acknowledged | 02 |
| 2026-08-06 06:58:44 | a.krishnan | Reorder point changed | 20% | 25% | 07 |
Entries cannot be modified or removed through the application, by any role, including system administrators.
Filter by user, site, action type, date range or the value that changed, then export the result set.
A read-only auditor role can review the full trail without the ability to touch operational configuration.
Eight report families ship configured. Everything else is built in the report builder by the people who need it, then scheduled and mailed out on its own.
By vehicle, driver, department, product and period.
On hand, ullage and reorder exposure across sites.
Receipts, suppliers and delivered against gauged variance.
Rolled by site, pump, product or cost center.
Pump throughput, uptime and service exposure.
Logins, actions and access review evidence.
Reconciliation, leak test history and adjustment records.
Raised, acknowledged, cleared, with time to response.
Roles are configurable rather than fixed. Start from the six below, then set what each one can see and do at the level of an individual module, site or action.
Enforced by role or globally, with recovery handled by administrators.
Connect your existing identity provider so joiners and leavers flow through automatically.
Length, complexity, rotation, reuse history and lockout thresholds set centrally.
Idle timeout, concurrent session limits and remote revocation of an active session.
| Role | Dashboards | Fuel operations | Configuration | User admin | Audit log | Scope |
|---|---|---|---|---|---|---|
| System administrator | All sites | |||||
| Regional manager | Assigned region | |||||
| Site manager | Assigned sites | |||||
| Operator | Single site | |||||
| Auditor | All sites, read only | |||||
| Read-only user | As assigned |
Filled circle: full access. Outlined: limited or read only. Dashed: no access. Every cell is configurable.
Reservo is built to SOC 2-aligned and ISO 27001-aligned control practices. Certification status and hosting region are confirmed in writing during procurement.
Reservo is not a fresh start. Inventory records, users, vehicles, drivers, cardholders, historical transactions, configuration and reporting history are migrated with integrity checks at every step, on a cutover plan that keeps fuel flowing.

Migration runs as a rehearsed pass with reconciliation reports before cutover, so record counts and totals are matched before anything is committed.
Site survey, hardware inventory and protocol confirmation. We agree the cutover sequence before anyone touches a gateway.
Cloud tenant stood up, edge gateways configured and commissioned site by site, hardware integration verified against live readings.
Data migrated in a rehearsed pass with reconciliation reports, then users provisioned into roles and site assignments.
Administrator and end-user training delivered remotely or on site, backed by documentation your team keeps.
Production cutover, validation testing and acceptance support, followed by a hypercare window with the implementation team still on the call.
Sessions are built around the roles you actually staff, not a generic product tour. Delivered remotely or on site, and recorded on request so the next hire gets the same version.
Incidents are tracked against defined response and resolution targets agreed in the service schedule, covering the software and the connectivity path between your site and the platform.
No. That is the point of the platform. Reservo reads from the island controllers, automatic tank gauges, dispensers, card readers and site controllers you already have, using native protocols wherever they exist. Replacing field equipment is a separate scope and is not required to go live.
The edge gateway keeps running. It continues to authorize and record transactions, keeps polling gauge readings, and preserves audit history to local storage. When connectivity returns it uploads everything in sequence and reconciles automatically. There is no manual synchronization step and no window where fueling has to stop.
Inventory records, user accounts, vehicles, drivers, cardholders, historical transactions, configuration and reporting history. Migration runs as a rehearsed pass with reconciliation reports before cutover, so you can see record counts and totals matched before you commit.
Yes. Permissions are configurable by module, location and function, on top of six starting roles. A site manager sees only their assigned sites, an auditor sees everything read only, and a contractor can be scoped to a single facility and a single product.
Facilities can be grouped however your organization is structured, with rollups at group and regional level and drilldown to a single pump. There is no cap on the number of facilities on a tenant.
Pricing is custom and scoped against your site count, tank count, integration complexity, data migration volume and support tier. We put a written scope and commercial schedule in front of you before any commitment.