DeepLeaf Yield DeepLeaf Yield

Security and privacy

How DeepLeaf Yield separates, stores, and protects your organization's data, and what DeepLeaf Yield handles for you.

The app's sign-in card, with a password field for the organization API key.
The app asks for a key before it shows any data.

Data separated per organization

  • Every farm, greenhouse, row, cycle, walk, and record belongs to one organization.
  • A key reads and writes only its own organization's data. Scoring jobs and places of other organizations answer as not found.

Keys

  • Keys are stored as hashes, not as the key itself.
  • A key is shown once, when it is created, and is never written to logs.
  • Each key is an admin key or a member key. Only admin keys manage keys and pay for the plan. Keys issued before roles existed are admin keys.
  • Your organization's admins revoke keys under Access keys in the app. A revoked key stops working on the next request. The last admin key can't be revoked, so the organization is never locked out.
  • Each key records when it was last used, to the minute, so unused keys are easy to spot.
  • A new organization's first admin key is collected once, with the claim code from its access request. DeepLeaf Yield stores only a hash of the claim code, never sends it by email, and the code stops working 30 days after the request. Too many unknown codes from one address are refused for a while.
  • If every admin key is lost, write to hello@deepleaf.io.

Web sessions

  • After sign-in, the browser holds the key in an HttpOnly cookie, which page scripts can't read.
  • The cookie is SameSite=Strict, so other sites can't send requests with it, and it is marked Secure over HTTPS.
  • It lasts 30 days. Sign out removes it from that browser.

What DeepLeaf Yield handles

  • Serving the app and API over HTTPS in production.
  • Running the detection models, storing your data, and keeping backups.
  • Fetching outdoor weather for greenhouses that have a location. Only the greenhouse latitude and longitude are sent to the weather data source.

The pages load no outside fonts, scripts, analytics, or trackers.

What you can do

  • Keep keys in a password manager, and don't paste them into shared documents or email.
  • Create one key per device or person, give it the member role unless it needs admin, and revoke keys that are no longer used.
  • Remember that a delete in the registry can't be undone from the app. Export the cycle to CSV first if you might need the numbers.