Where your data lives
Agronome.ai runs in Google Cloud's Toronto, Canada region (northamerica-northeast2). Your field boundaries, yield maps, soil samples, drone imagery, and agronomic records are stored and processed in Canada. Backups are kept in Canadian dual-region storage, so disaster-recovery copies stay inside the country too.
- In Toronto: all customer farm data, field boundaries, yield records, soil samples, drone outputs, and operational logs.
- In Canada (dual-region): backups, drone tile caches, exported reports.
- No customer data leaves Canada. No multi-region failover to the US, no global CDN holding plaintext data.
Aligned with PIPEDA (Canada's Personal Information Protection and Electronic Documents Act) and provincial privacy expectations for agricultural data sovereignty.
Your data, your call
Farmer data on Agronome.ai is organised around the open AgGateway ADAPT data model — the same grower, farm, field, and crop-zone hierarchy used by John Deere, Climate FieldView, and Bayer.
Getting your data back out does not depend on that, and does not require a negotiation. Boundaries download as ordinary GIS files any agronomist or FMIS can open.
- You own every field boundary, yield record, soil sample, and observation you upload.
- One-click export from the app: field and crop-zone boundaries as ESRI shapefile or GeoJSON, and your operations, equipment, crop zones, and trials as CSV.
- We don't train AI models on your data without your explicit, per-feature consent.
- Delete your account and your data is permanently removed from production within 30 days, from backups within 90.
- If we ever shut down, you'll get 90 days' notice and a one-click bulk export.
Encrypted everywhere
At rest
- AES-256 across Cloud SQL (Postgres), GCS object storage, Secret Manager.
- Third-party OAuth tokens (John Deere, CNH, PTX, DJI) AES-encrypted before reaching the database.
- Encryption keys managed by Google Cloud KMS with automatic rotation.
In transit
- TLS 1.2+ on all client connections (browser, mobile, API).
- Database connections use mutual TLS via Cloud SQL Auth Proxy with IAM-issued certificates.
- Internal service-to-service traffic stays inside a private VPC.
Least-privilege by default
Every action against the platform is authenticated, scoped to an organization, and gated by role. Internal services never share identities or credentials.
- Firebase Authentication with RSA-signed ID tokens, verified server-side on every request.
- Role-based access control per organization — Owner, Admin, Editor, Viewer — plus persona-aware feature gating (Grower, Consultant, Processor).
- Separate service accounts for each internal role (API, CI/CD, drone processing, alerting). No shared credentials.
- No static keys in CI: GitHub Actions authenticates to Google Cloud via Workload Identity Federation.
- Production deletion protection on the database and key resources.
Built on Google Cloud, hardened by default
We run on managed Google Cloud services so we inherit Google's physical security, hardware attestation, and DDoS protection out of the box. Everything customer-facing sits inside a private VPC in Toronto.
- Cloud Run for the API — serverless, autoscaling, regional. Egress through a private VPC.
- Cloud SQL for Postgres 16 + PostGIS — accessed only via Cloud SQL Auth Proxy with IAM. No IP allowlisting, no direct database TCP exposure.
- Cloud Storage for imagery, drone tiles, and exports — Canadian dual-region with private access.
- Cloud Batch for drone processing pipelines — runs in Toronto, pulls images from Canadian buckets.
- Same-origin web app — the React frontend and FastAPI backend serve from the same domain, eliminating cross-origin request exposure entirely.
Backups and disaster recovery
- Daily automated backups retained for 30 days in production.
- Point-in-time recovery enabled — we can restore your database to any moment in the last 7 days.
- Multi-zone high availability — the production database fails over automatically between Toronto availability zones if one zone goes offline.
- All backups stay in Canada. No cross-border replication.
Continuous observation, fast response
- Real-time alerting across error rates, latency, database health, drone pipeline failures, and authentication anomalies — 18 dedicated alert policies routed to engineering.
- Structured audit logging for authentication events, permission changes, and data exports.
- Uptime monitoring from external probes against the production API.
- Incident response commitment: we'll notify affected customers within 72 hours of confirming any security incident that may have exposed their data.
Trusted vendors, encrypted credentials
We connect to John Deere, CNH, PTX/AGCO, DJI, and several imagery providers on your behalf. Every credential they issue us is encrypted before it touches the database — only the agronome.ai application can decrypt them, and only when actively syncing your data.
What's in place — and what's next
We treat the security program as a product roadmap, not a checkbox. Here's what's running today and what we're committed to ship.
PIPEDA alignment
In placeControls aligned with Canada's federal privacy law for the data we hold today.
Encryption at rest & in transit
In placeAES-256 + TLS 1.2+ verified in every environment.
Cloud SQL IAM enforcement
In placeNo password-based database access. Proxy + IAM only.
Workload Identity Federation
In placeCI/CD uses short-lived tokens, not long-lived keys.
SOC 2 Type II audit
On roadmapAudit in progress — Q4 target.
Independent penetration testing
On roadmapAnnual third-party pen test commencing 2027.
Customer-managed encryption keys (CMEK)
On roadmapEnterprise customers will be able to supply their own KMS keys.
Common questions
Is my farm data ever sent outside Canada?
+
No. All customer data — field boundaries, yields, soil samples, drone imagery, operations records — is stored and processed in Toronto. Backups stay in Canadian dual-region storage. There is no US replication, no global CDN holding plaintext, no offshore support backend.
Can I export all my data?
+
Yes. Field and crop-zone boundaries export as shapefile or GeoJSON, and your operations, equipment, crop zones, and trials export as CSV — all from the app. No support ticket required, no fee, no contractual lock-in.
Do you train AI on my fields?
+
Not without your explicit consent. Any analytics, recommendations, or anomaly detection feature that uses your data for model training is opt-in per feature, and you can revoke that consent at any time. Aggregated, anonymized statistics (e.g. "Canadian potato yield averages") may be derived, but never with anything that identifies your operation.
What happens if Agronome.ai shuts down?
+
You'll receive 90 days' notice with a one-click bulk export of every field, yield record, sample, and operation. We have no right to retain your data past that window.
Are you SOC 2 certified?
+
Not yet — our SOC 2 Type II audit is in progress, with a Q4 target. The underlying controls — encryption, access management, monitoring, backups, network isolation — are operational today; what's underway is the independent third-party attestation that they are.
How do you handle a data breach?
+
We commit to notifying affected customers within 72 hours of confirming any security incident that may have exposed their data, with what was affected, what we know about the cause, and what we're doing about it. PIPEDA also requires this; we treat it as a floor, not a target.
Do you offer single sign-on (SSO) for enterprise customers?
+
SAML / OIDC SSO is on the enterprise roadmap. Today every user authenticates via Firebase with optional 2FA. If SSO is required for a procurement decision, talk to us — we have an integration path.
Who do I contact about a security concern?
+
security@agronome.ai. We monitor that inbox and will respond within one business day for genuine reports. Responsible disclosure details are on /security/responsible-disclosure.
Get in touch
For security questions, vendor due-diligence reviews, or to report a vulnerability, email security@agronome.ai.