Fuel distribution software: know the level without the drive, and keep the plan when the truck breaks down
Dispatch lives in one person's head, and when he takes a week off the run-outs start. We build the system that holds what he knows, around your fuel ERP, ATGs, QuickBooks or whatever you run: tank levels and an honest run-out forecast, delivery planning that respects compartments, ullage and hours of service, BOLs captured at the rack, and the 30-day record an inspector will ask for.
What fuel distributors should know before buying software
3 things that decide this
- 01A run-out doesn't just cost you a delivery. It stops a farm, a fleet or a generator, and the emergency drop that follows breaks the rest of your day's route, which is why a level sensor and a forecast pay for themselves in the trips you stop making rather than in anything a brochure promises.
- 02Most vendors selling AI routing are selling a solver, and we'd rather tell you that. Route planning here is constraint optimisation over compartment sizes, product compatibility, tank ullage and driver hours, and the honest AI contribution is the demand forecast feeding it.
- 03Book stock and measured stock never agree exactly. Variance has at least six causes that look identical in a daily number, and only a statistical window separates a leak from a meter from a short load, which is why we won't show your dispatcher a daily variance figure and call it a signal.
Eight places a fuel distributor's week leaks time, in your words
Eight areas our audits keep finding at distributors, bulk plants and c-store chains, in the order a week meets them.
"I don't know what's in that tank until someone drives out and sticks it."
Every unmonitored tank is a truck roll to read a number. We add level telemetry where the site has power and signal, offline capture where it doesn't, a consumption forecast on usage and weather, and a delivery trigger into your dispatch. A slightly wrong tank chart makes every reading wrong, so we store the chart with the tank, version it, and compare every prediction against what the truck actually dropped.
"Dispatch is one person's head. If he's out, we guess."
Morning routing is the part everybody demos, and it's the easy part. We build planning that respects compartments, product compatibility, ullage, delivery windows, hours of service and hazmat routes, and then we build for the re-plan, because a route that's mathematically ideal but pushes a driver past their limit isn't clever, it's illegal.
"Half my day is re-planning the plan."
A customer calls in an emergency, a site is blocked, a driver runs short of hours, and the morning's plan is gone by ten. The system surfaces the exception, proposes the reshuffle and shows what it breaks; your dispatcher commits it. Full autonomy isn't credible here and your dispatcher won't accept it, which is why we don't sell it.
"The BOL comes back coffee-stained and the gallons don't match."
The bill of lading is the legal record of what moved, and it's created on a terminal's system you don't control. We capture it at the rack with OCR on the driver's phone, hold the terminal document beside your delivery record, and flag differences outside a tolerance you set rather than every difference, because temperature correction means loaded and delivered volumes can both be correct.
"The numbers don't match and I can't tell if it's a leak, a meter, or theft."
Six causes look identical in a daily number: temperature, meter drift, short loads, water ingress, theft and a genuine release. We run reconciliation over a statistical window and show you which of the six the evidence supports, so you send a truck where it's warranted and not where it isn't. Note the regulatory bar the vertical works to: SIR must detect a 0.2 gph leak rate or a 150-gallon release within 30 days, per 40 CFR 280.43.
"The ATG says there's an alarm. It says that every week."
An alarm that's usually wrong trains your people to clear alarms without reading them, which is exactly how a real release gets missed. We de-duplicate, prioritise against that site's normal rather than a fleet-wide threshold, escalate to somebody who can act, and log who acknowledged what. Your certified detection method stays the method.
"The inspector asked for twelve months and we had a binder with gaps."
A missing record is the violation, even when the work was done properly. We schedule the walkthrough per asset and per site, capture a result per area checked rather than one verdict for the whole site, hold photos and the time the work happened, keep it immutable, and escalate a deficiency into a work order a contractor closes with evidence.
"I have four back-office systems and none of them talk."
Acquisitions leave you with sites on different systems and a roll-up that means nothing because the underlying capture is inconsistent. We standardise how a delivery, an inspection and a BOL get recorded first, then build the dashboards and the environmental reports on top, with per-organisation separation so a division or a customer sees only theirs.
A fuel distributor's week, and where the machine takes over
Four stations of your week. Pick the system you'd want written to; your fuel ERP, ADD Systems, PDI, P2 and the rest follow the same pattern to the depth their access model allows.
Station 01 · The tank level nobody knows
- Today
- Someone drives out and sticks your tank. A run-out stops your customer's farm, fleet or generator, and the emergency delivery breaks your day's route.
- What we automate
- Level telemetry where the site has power and signal, offline capture on a phone where it doesn't, a consumption forecast on usage and weather, run-out alerts, and a delivery trigger written into your dispatch.
- What stays human
- Your dispatcher decides what to do with the trigger. A forecast is a forecast, and it tells you so.
Writes to Enverus OpenInvoiceNot an OpenInvoice station.
Station 02 · Dispatch and the day that breaks
- Today
- Your dispatch is one person's head. A truck breaks down and your plan is gone; the replacement plan drops your driver over hours of service.
- What we automate
- Delivery planning that respects compartments, compatibility, ullage, hours of service and hazmat routes, exception handling when the day breaks, and driver paperwork and BOLs captured on the phone at the rack.
- What stays human
- Your dispatcher owns the plan. It proposes; your dispatcher commits.
Writes to Enverus OpenInvoiceNothing.
Station 03 · BOLs and the variance
- Today
- Your BOLs arrive as phone photos, your book stock and measured stock never agree, and nobody can tell a leak from a meter from theft in a daily number.
- What we automate
- OCR and matching for BOLs, statistical reconciliation over a window that separates temperature, meter drift, short loads, water and theft from a real loss, and a variance view that says where to send a truck.
- What stays human
- You decide when a variance becomes an investigation, and the regulator's method decides when it's a release.
Writes to Enverus OpenInvoiceNothing.
Station 04 · The 30-day inspection record
- Today
- Your walkthrough happens, mostly, and your record is a binder with gaps. When an inspector asks you for twelve months, the gaps are the violation.
- What we automate
- Inspections scheduled per asset and per site, dynamic checklists on a phone, photos and timestamps, an immutable record with a gap shown as a gap, deficiencies escalated to a work order, and audit and compliance reports exported on demand.
- What stays human
- Your inspector still walks the site and signs. We make the record survive, searchable and honest.
Writes to Enverus OpenInvoiceNothing.
The certified detection method, the dispatcher's commit and the inspector's signature stay with a person at every station.
We don't replace your fuel ERP, your ATGs or QuickBooks. We build what they leave to your office manager.
ADD Systems, PDI, DM2 and the rest are good at what they were built for, and most distributors we talk to are buying around their back office rather than replacing it. Replacing it doesn't close the gaps anyway; it moves them, and it costs you a year. The gaps stay the same shape: the tank nobody monitors, the alarm nobody reads, the BOL that arrives three days late, the roll-up nobody trusts.
So the access model matters more than the brand. Your ATG vendors publish their own feeds and Veeder-Root, Franklin Fueling and OPW each expose data differently, so an estate of any age gives you device variance rather than one integration. Your back office owns fuel inventory and stays the system of record, winning any conflict. QuickBooks takes what your accountant allows. Bulk plants and rural cardlocks have marginal signal by nature rather than by fault, so capture is offline-first and readings buffer at the edge and reconcile on reconnect. And equipment near fill points, vents and dispensers has to be rated for a classified area, which narrows your hardware options long before price does.
We confirm what each of your systems actually exposes during the audit and design to that, and where the route in stops we build a reviewed queue your staff accept with one click rather than re-keying.
- 01Your back office keeps fuel inventory and wins any conflict; we write beside it, to the depth it allows.
- 02Offline-first capture for bulk plants and rural cardlocks; readings buffer and reconcile on reconnect.
- 03Hazardous-area classification is scoped before any device is chosen, not after it's bought.
Software on top of a certified detection method, never instead of it. We write that down first.
Fuel and oilfield operations sit under rules that don't bend for software: release detection has to meet the performance standards in 40 CFR 280 and be certified as a method, the 30-day walkthrough record is the compliance artefact whether or not the inspection happened, and a field ticket is a billing document an operator will audit. So every build starts with a one-page map of what the software records, what it only proposes, and where a person signs.
What follows is simple to state, and we put it in writing. We triage, de-duplicate and escalate alarms from your certified method; we never claim to be the method. Every inspection record is timestamped, photo-backed and immutable, and a gap stays visible as a gap. Tickets and invoices are approved by a person before they go to an operator's portal. And every automated touch is logged so an inspector or an auditor can read what happened, and when.
- 01Release detection stays with the certified method; we add triage, escalation and the record.
- 02Inspection records immutable and gap-honest; tickets and invoices approved by a person.
- 03Tank charts are stored with the tank and versioned, and every predicted level is checked against the volume actually delivered.
“They will treat your vision like their own and build it that way.”
Ron Klabunde · Founder, SmartREI ↗
“TankAware has revolutionized how we manage petroleum sites. The real-time data and automation have exceeded expectations.”
Blake Sutherland · President, Sutherland Excavating Ltd.
Some of the systems we have shipped
- AuditFree. We count the trips your people make just to read a level, read a month of your alarms and what happened to each one, and follow one delivery from the rack to the invoice.
- DiagnoseWe map the path into your ERP, ATG feeds and operator portals, and ride along on a site round or a ticket's journey.
- BuildFixed price from the diagnostic. Tested on your real sites, real tickets and real alarms, offline-first, under NDA.
- RunMonitoring, a named engineer, and the first two months of maintenance free.
Best fit: ten or more sites or trucks, or an oilfield services company with a ticket-to-cash problem, and systems you've outgrown in places. Not a fit yet: a single-site operator who needs a sensor and a text, and we'll say so. You can stop after any stage; the audit note is yours either way.
Before you book
01Will tank monitoring pay for itself in avoided truck rolls?+
That's the right way to frame it, and the answer depends on how many tanks you currently check by driving to them. Sutherland Excavating Ltd. reports 30% less operational overhead after TankAware went live, and 40% fewer manual errors. Count your monthly level-check trips and your emergency deliveries before the call, because those two numbers drive the whole case and we'd rather work from yours than from an average.
02Our dispatcher doesn't want software. How do you handle that?+
Take him seriously, because he's usually right about why the last system failed. His knowledge is real and mostly undocumented: which customer never takes a Friday drop, which yard is impossible after rain, which tank reads high in summer. We build to capture those rules rather than override them, and a plan a dispatcher can edit gets used while a locked one gets abandoned in week two.
03Can software be our release detection method?+
No. Regulated detection methods have to meet the performance standards in 40 CFR 280 and carry certification, so your certified method stays the certified method. What software adds on top is real: de-duplicating alerts, ranking them by likelihood, escalating to a person and holding the evidence trail. Fixing the alarm that's usually wrong is an engineering problem worth solving, and it's a different claim from being the detection method.
04How do you reconcile a BOL against what actually arrived?+
By expecting the two to differ and modelling why. Petroleum expands and contracts with temperature, so a loaded figure and a delivered figure can both be correct, and mixing gross and net volumes silently corrupts every reconciliation downstream. We capture the delivery record at the drop with your driver present, hold the terminal document beside it, and flag differences outside a tolerance you set rather than every difference.
05Does OSHA's process safety management rule apply to our fuel storage?+
Usually not, and there's a separate page on this. Atmospheric storage tanks are largely written out of the rule, which surprises operators who've been told otherwise by a consultant. Your live obligations are far more likely to come from 40 CFR 280 and from your state's implementing agency, which runs its own EPA-approved programme and is often stricter than the federal floor. We build intervals and retention as configuration for exactly that reason.
06We run several yards on different systems. Where do you start?+
With the tanks and the records, not the reporting layer. Multi-site operators usually want a dashboard first, and a dashboard over inconsistent site data just makes the inconsistency visible faster. Standardise how a delivery, an inspection and a BOL get captured, get the same approval flow everywhere, and then the roll-up means something. Shift Link took the same route for multi-site workforce compliance.
A senior engineer, not a sales rep
Abdul Basit founded Hashlogics in 2017, and the team runs from Lahore with a US LLC. Clients rate the work 5.0 on Clutch, and in 2026 it was named Best AI-Native Software House of the Year at TechNova. TankAware, the AI and IoT petroleum site platform we built for Sutherland Excavating Ltd. in Canada, is live and we can show it to you.
Your audit call is with an engineer who has read inspection logs, ATG alarm histories and field tickets like yours. Bring last month's numbers if you have them, and we'll work from those.
- NDA before the first conversation.
- No pitch on the call. A note you could hand to another firm.
- Fixed price after the diagnostic, so the number isn't a guess.

Go deeper
- Oil and gas →The hub: all eight areas, and which page owns each one.
- Site monitoring for fuel and oilfield →Tank levels, alarm triage and the 30-day inspection record.
- Field operations for oilfield services →Field tickets, approvals, dispatch and ticket-to-cash.
- Custom software for oil and gas →Vendor portals, multi-tenant separation and the numbers across sites.
- Does OSHA PSM apply to fuel storage? →Usually not. Atmospheric tanks are written out of the rule.
- What should a tank monitoring system alert on? →Triage on top of the certified method, not instead of it.
- Packaged tank monitoring vs a custom site platform →When to buy the monitor, and when the layer across them is the job.
- An unanswered alarm is worse than no alarm →Why alarm fatigue is the failure mode, and what fixes it.

