Security & compliance

How we protect your data

Growing data is commercially sensitive. BeeGrow AI combines tenant isolation, server-side access control, audit records and deployment safeguards for customer production environments.

Application controls

Controls built into the platform

Tenant isolation

Tenant context is enforced through the gateway and data-access layers, backed by tenant-isolation release tests.

Role-based access

Authentication and permission checks are enforced server-side through the gateway and domain services.

Audit records

Critical state-changing workflows use actor-aware audit records with timestamps and operational context.

Encryption and secrets

Production traffic uses TLS and secrets are managed outside source control. Hosting encryption and key-management responsibilities are documented for each deployment.

Backups and recovery

Production service schedules define backup frequency, off-host retention, restore testing and recovery objectives.

Monitoring

Service health, operational logs, ingestion continuity and incident alerts support production operations.

Data protection

UK GDPR controls

BeeGrow AI is built by a UK company. The production hosting region, sub-processors, retention periods and transfer safeguards are named in the signed customer documents.

  • Hosting region and sub-processors disclosed in final data processing terms
  • Lawful basis documented for each category of personal data
  • Retention and deletion periods defined in customer terms
  • Data-subject requests handled as the data processing terms set out
  • Export and deletion carried out as your agreement specifies
Certification support

Records the product supports

The platform is not a certification, and no software can be. What it holds is the operational record an auditor asks to see. Fitness for a particular scheme must be verified against that scheme before an audit.

  • Batch identity carried from the cultivation plan through harvest, storage and dispatch
  • Harvest, grading and storage events timestamped against the batch and the person who recorded them
  • The environmental history of the zone a batch grew in, across the whole cycle
  • Scouting and disease observations as named classifications with severity and location
  • An audit trail of who changed what, when, and for what stated reason
  • Retention requirements agreed for your deployment

We do not generate scheme-specific paperwork. There is no HACCP plan builder, no plant-passport issuer and no spray-record module. If your scheme needs those, they stay where they are today and BeeGrow AI supplies the underlying record.

Reporting a vulnerability. If you believe you have found a security issue, email hello@beegrow.ai with enough detail to reproduce it. We will acknowledge within two working days and keep you updated until it is resolved. Please give us a reasonable window to fix the issue before disclosing it publicly. We will not pursue legal action against researchers who act in good faith and avoid privacy violations or service disruption.

Request our security documentation

Next step

Need to run this past your IT team?

We are happy to complete a security questionnaire, walk your team through the architecture, or answer a due-diligence list. Ask.

  • Walkthrough led by someone who has built the system
  • We map your zones, crops and sensors before the call
  • Straight answers on what fits and what does not