Equipment Guides

Passport POS & Dispenser Integration: Compliance Guide

September 29, 2026|12 min read
Three vintage gas pumps displayed indoors

Figures in this article are being re-verified.

Penalty amounts, deadlines and regulatory citations are being checked against primary sources. Until this notice clears, confirm any figure with your state program before acting on it. Not yet verified. Not legal advice.

Why the Passport POS Is a Compliance Hub, Not Just a Cash Register

The Passport point-of-sale system, originally developed by Gilbarco and now marketed under the Invenco by GVR brand following Gilbarco Veeder-Root's retail solutions rebrand in July 2023, is one of the most widely deployed site controllers in U.S. fuel retail. It does far more than ring up transactions: it authorizes outdoor payment terminals, communicates with automatic tank gauges (ATGs), manages price changes, controls dispenser grades, and generates the records that regulators and payment card brands want to see.

That central role means a misconfigured or poorly maintained Passport installation creates compliance exposure across multiple regulatory frameworks simultaneously—EPA underground storage tank (UST) rules, PCI DSS payment security standards, weights-and-measures law, and state-level fuel quality requirements. This guide walks through each integration point and the compliance obligations that attach to it.

Understanding the Passport Ecosystem

Before diving into compliance, it helps to map the components the Passport POS communicates with on a typical forecourt.

Component Role in the Passport Ecosystem Primary Compliance Touchpoint
Gilbarco Encore dispensers Fuel delivery and grade selection; receive price and authorization commands from Passport Weights & measures (NIST HB 44); EPA release detection
FlexPay outdoor payment terminals Card acceptance at the pump; communicate authorization requests through Passport to the payment processor PCI DSS; EMV chip mandate
ATG (e.g., Veeder-Root TLS series) Tank inventory, leak detection, and alarm reporting; Passport reads ATG data for reconciliation 40 CFR 280.41–280.45 release detection; 40 CFR 280.36 walkthrough inspections
Back-office / head-office software Receives sales, inventory, and exception data from Passport for accounting and variance analysis Record retention; financial responsibility documentation
Price sign controllers Passport can push price changes to roadside LED signs State weights-and-measures price posting rules

Dispenser Integration: Price Control and Grade Authorization

How Passport Controls the Dispenser

The Passport POS communicates with Gilbarco Encore dispensers (and, in mixed-brand sites, with Wayne Ovation dispensers and others) over a site controller protocol. When a customer lifts the nozzle or taps a card at the FlexPay terminal, the dispenser requests authorization from Passport, which checks the payment method, applies the correct price per grade, and releases the pump. This handshake is where several compliance obligations converge.

Price Accuracy and Weights-and-Measures Compliance

The price programmed in Passport must match the price posted on the roadside sign and the price printed on the receipt. A mismatch—even a fraction of a cent—can trigger a weights-and-measures violation during a state inspector's test. Under NIST Handbook 44 (2026 edition), Section 3.30, the maintenance tolerance for a retail motor-fuel dispenser on a test draft of 10 gallons or less is 1 cubic inch plus 1 cubic inch per indicated gallon (for example, 6 cubic inches on a 5-gallon draft); the acceptance tolerance is one-half that amount. These are hardware tolerances, but price-programming errors in the POS compound them.

Passport's price-change workflow requires an authorized user to enter the new price, confirm it, and push it to the dispensers. Best practice is to treat every price change as a two-person verification: one employee enters the price, a second confirms the dispenser display and the roadside sign before the first transaction at the new price. For more on dispenser inspection requirements, see our guide on weights & measures compliance and dispenser inspections.

Grade Blending and Ethanol Labeling

Sites that blend mid-grade from regular and premium (a "blender" dispenser configuration) rely on Passport to set the blend ratio. If the ratio drifts or is entered incorrectly, the octane of the dispensed product may not match the posted grade. Fuel quality standards for gasoline are governed by 40 CFR Part 1090, which replaced the former Part 80. Ethanol content labeling on the dispenser face is a separate requirement enforced by state weights-and-measures agencies. Passport's grade configuration screen must reflect the actual product being delivered from each tank—verify this every time you receive a delivery of a different blend or ethanol level.

ATG Integration: Release Detection Records the Passport Must Support

The 30-Day Release Detection Obligation

Under 40 CFR 280.41(a), UST owners and operators must perform release detection at least every 30 days using one of the methods listed in 40 CFR 280.43. Automatic tank gauging (ATG) qualifies under 40 CFR 280.43(d). The Passport POS, when integrated with an ATG such as the Veeder-Root TLS series, can pull inventory data and flag discrepancies—but the operator must ensure that integration is active and that alarms are not being silenced at the POS without investigation.

Inventory control under 40 CFR 280.43(a) requires that monthly reconciliation detect a release if the variance exceeds 1.0% of flow-through plus 130 gallons. Passport's back-office reporting can generate the daily and monthly reconciliation data needed to meet this standard, but only if the dispenser meter readings are being accurately captured and the ATG stick readings are entered or transmitted correctly. For a deeper look at daily reconciliation workflows, see our article on daily fuel inventory reconciliation and catching tank variances early.

Record Retention Requirements

Under 40 CFR 280.45, release detection records must be retained for at least 1 year; records of annual operation tests must be kept for 3 years. Passport and its connected back-office software are typically the primary repository for these records at retail sites. Operators should confirm that:

  • Daily inventory records are being exported or backed up, not just stored on the local Passport hard drive.
  • ATG alarm logs are preserved and linked to the corresponding investigation or corrective action record.
  • The system clock on the Passport is accurate—timestamps on release detection records are reviewed during EPA and state UST inspections.

Walkthrough Inspection Documentation

40 CFR 280.36 requires operator walkthrough inspections at least every 30 days for spill prevention and release detection equipment. While the Passport POS does not perform the physical inspection, it is often used to log inspection results or to print the checklist. Ensure your site's inspection log references the ATG readings pulled from Passport on the inspection date.

Outdoor Payment Terminal Integration: PCI DSS and EMV

FlexPay Terminals and the Passport Authorization Chain

Gilbarco's FlexPay outdoor payment terminals (the FlexPay II, IV, and 6 product lines) communicate card data to the Passport site controller, which forwards authorization requests to the payment processor. This architecture means the Passport is a node in the cardholder data environment (CDE) as defined by PCI DSS. The version of Passport software running at your site, the network segmentation between the forecourt and the back office, and the encryption method used by the FlexPay terminal all affect your PCI DSS scope and your Self-Assessment Questionnaire (SAQ) category.

EMV chip-and-PIN compliance at the outdoor terminal is enforced through the payment brands' liability shift rules. Sites running FlexPay terminals that are not EMV-enabled—or running Passport software versions that do not support the EMV kernel—bear liability for counterfeit card fraud at the pump. Confirm with your payment processor and your Invenco by GVR service provider that both the terminal firmware and the Passport software version are on a currently supported, EMV-capable release. For a detailed look at how payment processing proposals are structured, see our guide on how to read a gas station payment processing proposal.

Network Segmentation and Software Updates

PCI DSS requires that systems storing, processing, or transmitting cardholder data be isolated from general business networks. On a Passport installation, this typically means the POS network (connecting Passport to FlexPay terminals and the payment processor) must be on a separate VLAN or physical segment from the store's Wi-Fi, loyalty kiosk, and office computers. Passport software updates that include security patches must be applied promptly—running an end-of-life Passport version is a PCI DSS finding and a practical security risk.

Price Sign Integration: Posting Compliance

Many Passport installations include an interface to roadside LED price signs. When Passport pushes a price change to the sign controller, the posted price updates automatically. This is convenient but creates a compliance dependency: if the Passport-to-sign communication fails, the sign may display a stale price while the dispenser charges the new one. State weights-and-measures laws require that the posted price match the price charged. Build a verification step into your price-change procedure to confirm the sign updated before the first transaction at the new price.

Back-Office Integration: Reconciliation and Financial Responsibility

Matching POS, Dispenser, and ATG Data

The Passport POS is the source of record for fuel sales volume and dollar amounts. Back-office software—whether a dedicated petroleum retail platform or an accounting package—pulls this data to reconcile against ATG inventory readings and bank settlement figures. Unexplained variances between Passport sales data and ATG inventory can indicate meter drift, theft, or a release. Under 40 CFR 280.43(a), a variance exceeding 1.0% of flow-through plus 130 gallons triggers further investigation under the release detection rules.

For a step-by-step reconciliation workflow, see our article on back-office reconciliation: matching POS, dispenser, and bank data.

UST Financial Responsibility

Under 40 CFR 280.93, petroleum marketing facilities—which includes virtually every retail gas station—must demonstrate financial responsibility of at least $1,000,000 per occurrence. The Passport POS does not directly satisfy this requirement, but the reconciliation records it generates are often submitted as evidence of operational compliance during state UST financial responsibility audits. Keep your insurance certificates, state fund enrollment documentation, and Passport-generated inventory records in the same compliance file.

Compliance Checklist: Passport POS Integration Audit

Use this checklist during your quarterly site review or before a state UST inspection.

Dispenser and Price Configuration

  • ☐ Prices in Passport match posted roadside sign prices and receipt prices for all grades
  • ☐ Grade blend ratios (if applicable) match current product in each tank
  • ☐ Ethanol content labels on dispenser faces match Passport grade configuration
  • ☐ Dispenser meter calibration records are current and on file

ATG and Release Detection

  • ☐ Passport-to-ATG communication is active; no unacknowledged alarms in the ATG log
  • ☐ Daily inventory reconciliation is being run and saved (retain at least 1 year per 40 CFR 280.45)
  • ☐ Monthly variance calculation confirms compliance with the 1.0% of flow-through plus 130 gallons threshold (40 CFR 280.43(a))
  • ☐ ATG annual operation test records are on file (retain 3 years per 40 CFR 280.45)
  • ☐ Passport system clock is accurate; verify against an authoritative time source

Payment Terminal and PCI DSS

  • ☐ FlexPay terminal firmware is on a currently supported, EMV-capable version
  • ☐ Passport software version is current and not end-of-life
  • ☐ POS network is segmented from general business and guest Wi-Fi networks
  • ☐ Last PCI DSS self-assessment questionnaire is complete and on file
  • ☐ Payment processor has confirmed current EMV liability shift status for outdoor terminals

Records and Documentation

  • ☐ Passport data is backed up off-site or to a cloud repository daily
  • ☐ Walkthrough inspection logs reference ATG readings from Passport on each inspection date
  • ☐ Price-change log is maintained showing who changed the price, when, and what the new price was
  • ☐ Exception reports (voids, overrides, manager keys) are reviewed weekly

Common Integration Failures and How to Prevent Them

Failure Mode Compliance Risk Prevention
ATG communication loss (Passport shows no tank data) Release detection gap; 40 CFR 280.41 violation; up to $29,980/tank/day (as of 2025-01-08, 40 CFR 19.4, 90 FR 1377) Monitor ATG communication status daily; set Passport alarm for communication failure
Price mismatch between Passport and roadside sign State weights-and-measures violation; potential consumer fraud claim Two-person price-change verification; automated sign-confirmation step
Outdated Passport software version PCI DSS non-compliance; EMV liability exposure Subscribe to Invenco by GVR software update notifications; schedule annual software review
Unacknowledged ATG alarms silenced at POS Potential unreported release; 40 CFR 280.53 requires reporting releases exceeding 25 gallons within 24 hours Require manager sign-off on all alarm acknowledgments; log investigation steps
Passport data not backed up Loss of release detection records required under 40 CFR 280.45; loss of payment dispute evidence Automated daily backup to off-site or cloud storage; test restore quarterly

Penalty Exposure When Integration Fails

Operators sometimes underestimate the financial stakes of a POS integration failure that creates a UST compliance gap. Federal civil penalties for UST violations can reach $74,943 per day (as of 2025-01-08; 40 CFR 19.4, 90 FR 1377). Notification and requirement violations—such as failing to maintain required release detection—can reach $29,980 per tank per day (as of 2025-01-08; 40 CFR 19.4, 90 FR 1377). Note that OMB memorandum M-26-11 (April 17, 2026) cancelled the 2026 inflation adjustment, so the 2025 amounts remain in force.

These are federal maximums; state implementing agencies often have their own penalty schedules. A single site with four USTs that goes 30 days without valid release detection records faces potential exposure that dwarfs the cost of a service call to restore ATG communication.

Working with Your Service Provider

Invenco by GVR (the current brand for Passport POS) and its authorized service network provide software updates, hardware support, and integration services. When scheduling service, be specific about compliance-driven needs:

  • Request documentation of the software version installed and its PCI DSS validation status.
  • Ask for a written confirmation that ATG communication protocols are configured correctly for your specific ATG model and firmware version.
  • Confirm that the FlexPay outdoor payment terminals are on a firmware version that supports the EMV kernel required by your payment processor.
  • Request a test of the price-sign interface after any software update that touches the price-control module.

For a broader comparison of site controller options, the article on Gilbarco Passport vs. Verifone Commander covers the architectural differences between the two leading platforms.

Next Steps: Action Items for Operators

  1. Audit your current Passport software version against the Invenco by GVR supported-versions list. If you are on an end-of-life version, schedule an upgrade before your next PCI DSS assessment period.
  2. Verify ATG communication by pulling a current inventory report from Passport and comparing it to a manual stick reading. If they diverge beyond normal meter tolerance, investigate before your next 30-day release detection deadline.
  3. Review your price-change procedure to ensure it includes a sign-verification step and a written log entry for every change.
  4. Confirm backup and retention of Passport data meets the 1-year minimum for release detection records (3 years for annual operation tests) under 40 CFR 280.45.
  5. Schedule a network segmentation review with your IT provider or PCI DSS qualified security assessor to confirm the Passport POS network is properly isolated.
  6. Train your manager-level staff on the alarm acknowledgment policy—no ATG alarm should be silenced without a documented investigation, given the 24-hour reporting requirement under 40 CFR 280.53 for releases exceeding 25 gallons.
  7. Review your financial responsibility documentation to confirm you meet the $1,000,000 per-occurrence requirement under 40 CFR 280.93 and that your Passport-generated records are organized to support an audit.

Sources

Was this helpful?
Disclaimer: Always verify with your state UST program. Regulations change.