Security and privacy
How DeepLeaf Yield separates, stores, and protects your organization's data, and what DeepLeaf Yield handles for you.
Data separated per organization
- Every farm, greenhouse, row, cycle, walk, and record belongs to one organization.
- A key reads and writes only its own organization's data. Scoring jobs and places of other organizations answer as not found.
Keys
- Keys are stored as hashes, not as the key itself.
- A key is shown once, when it is created, and is never written to logs.
- Each key is an admin key or a member key. Only admin keys manage keys and pay for the plan. Keys issued before roles existed are admin keys.
- Your organization's admins revoke keys under Access keys in the app. A revoked key stops working on the next request. The last admin key can't be revoked, so the organization is never locked out.
- Each key records when it was last used, to the minute, so unused keys are easy to spot.
- A new organization's first admin key is collected once, with the claim code from its access request. DeepLeaf Yield stores only a hash of the claim code, never sends it by email, and the code stops working 30 days after the request. Too many unknown codes from one address are refused for a while.
- If every admin key is lost, write to hello@deepleaf.io.
Web sessions
- After sign-in, the browser holds the key in an HttpOnly cookie, which page scripts can't read.
- The cookie is SameSite=Strict, so other sites can't send requests with it, and it is marked Secure over HTTPS.
- It lasts 30 days. Sign out removes it from that browser.
What DeepLeaf Yield handles
- Serving the app and API over HTTPS in production.
- Running the detection models, storing your data, and keeping backups.
- Fetching outdoor weather for greenhouses that have a location. Only the greenhouse latitude and longitude are sent to the weather data source.
The pages load no outside fonts, scripts, analytics, or trackers.
What you can do
- Keep keys in a password manager, and don't paste them into shared documents or email.
- Create one key per device or person, give it the member role unless it needs admin, and revoke keys that are no longer used.
- Remember that a delete in the registry can't be undone from the app. Export the cycle to CSV first if you might need the numbers.