Skip to main content
Menu

Security and data

Security and data boundaries for an internal MVP and selective private beta.

The public website is separate from Platform environments. Public forms accept high-level context only. Private-beta data and access are governed through separately agreed terms.

Public website

Public forms accept high-level context only.

The public website does not create a Platform account or product workspace. Detailed material is exchanged only after an appropriate scope, data route and responsible parties are agreed.

Public website data may include
Contact details, organisation, role, high-level project context, consent and technical form metadata.
The public form must not accept
Confidential project files, supplier-confidential documents, special-category personal data, credentials or regulated operational data.

Current product boundary

Scope before access.

The core Platform workflow operates internally. Selected organisations may receive scoped private-beta access after user, data, confidentiality, responsibility and support conditions are agreed.

Private-beta scope

Before access, define organisation, authorised users, roles, purpose, modules, data categories, source rights, hosting region, subprocessors, retention, export, deletion, confidentiality, support, incident contact and professional responsibilities.

Security principles

Least-privilege access, separate organisation scope, encryption in transit, encryption at rest where supported, secrets management, logging, backups, data minimisation, defined retention, controlled export, deletion process, model/provider review and an incident route are assessed for the agreed scope. Crop Urbanis does not call these certified controls.

AI data handling

AI processing in private beta is limited to the agreed purpose and data categories. Model providers, regions, retention and training conditions are reviewed as part of the beta scope. Crop Urbanis does not use confidential beta data to train public models unless separately authorised.

Professional boundary

Qualified responsibility remains with the organisation and professionals.

Platform outputs support project work. The organisation and qualified professionals retain responsibility for agronomy, engineering, safety, regulation, supplier confirmation, commercial decisions and commissioning.

Certifications
Crop Urbanis does not claim security certifications unless they are formally obtained.

Discuss private-beta data requirements.

Start with high-level context. If there is a fit, Crop Urbanis will define an appropriate controlled route before confidential material is exchanged.