At AI Farming Canada, protecting the security and integrity of our users' data is a core responsibility. This Security Policy describes the technical, organizational, and procedural measures we use to safeguard the personal information, plant photos, IoT sensor data, and transaction details processed through aifarming.ca, our mobile application, and the AI Farming Marketplace (collectively, the "Services").
This Policy should be read together with our Privacy Policy and Terms and Conditions. While we take extensive precautions to protect your data, no system can guarantee absolute security, and we encourage users to also follow good security practices on their own devices and accounts.
2. Data Encryption
- In transit: All data exchanged between your device and our servers — including login credentials, plant photos, IoT sensor readings, and payment information — is encrypted using HTTPS/TLS.
- At rest: Sensitive data, including passwords, is encrypted using industry-standard algorithms before being stored in our databases. Passwords are never stored in plain text; they are hashed using a strong, salted hashing function.
- Backups: Encrypted backups are maintained to support recovery in the event of data loss, hardware failure, or a security incident.
3. Payment and Financial Data Security
- All subscription billing and Marketplace payments are processed through PCI DSS-compliant third-party payment processors.
- AI Farming does not store full credit card numbers, CVV codes, or other sensitive cardholder data on our own servers.
- Payment tokens and transaction identifiers used internally cannot be reverse-engineered to reveal full card details.
4. Account and Access Security
- Authentication: User accounts are protected by password-based authentication. We encourage users to choose strong, unique passwords and enable any available multi-factor authentication options.
- Session management: Login sessions are secured with encrypted tokens and time-limited sessions to reduce the risk of unauthorized access.
- Role-based access: Internally, access to user data is restricted based on job role and business need. Employees and contractors are granted only the minimum level of access required to perform their duties (the "principle of least privilege").
- Account monitoring: We monitor for unusual login patterns, such as repeated failed login attempts or access from unfamiliar locations, and may temporarily lock or flag accounts showing suspicious activity.
5. Infrastructure and Cloud Security
- Our Services are hosted on reputable cloud infrastructure providers that maintain independent security certifications (such as ISO 27001 and SOC 2).
- Production systems are protected by firewalls, network segmentation, and intrusion detection/prevention systems.
- Software and infrastructure components are kept up to date with security patches, and we conduct periodic vulnerability scans of our systems.
- Access to production infrastructure is restricted to authorized personnel and logged for audit purposes.
6. AI Systems and Uploaded Content Security
- Photos and other content submitted for AI Plant Health Scan or AI Chat processing are transmitted and stored using the same encryption standards described in Section 2.
- Access to AI processing pipelines and any third-party AI infrastructure providers we use is governed by contractual confidentiality and data-protection obligations.
- We apply reasonable safeguards to prevent uploaded content from being used outside the scope described in our Privacy Policy.
7. IoT Device Security
- Data transmitted from connected IoT soil and climate sensors is encrypted in transit before reaching our servers.
- Users are responsible for securing their own local networks and device credentials, as we do not control the physical security or network environment of user-owned hardware.
- Where AI Farming-branded devices are sold through the Marketplace, we recommend following the manufacturer's setup instructions, including changing any default device passwords upon installation.
8. Marketplace Transaction Security
- Buyer-seller messages and order details within the Marketplace are transmitted over encrypted connections.
- Shipping addresses and contact information shared between buyers and sellers are limited to what is necessary to complete a transaction.
- We monitor Marketplace activity for signs of fraud, fake listings, or account takeover attempts, and may suspend accounts or transactions flagged as high-risk pending review.
9. Employee Access and Training
- All employees and contractors with access to user data are subject to confidentiality obligations.
- Access to sensitive systems requires individual authentication; shared credentials are prohibited.
- Relevant staff receive periodic training on data protection practices, phishing awareness, and secure handling of user information.
10. Security Monitoring and Incident Response
- We maintain logging and monitoring across our production systems to detect unauthorized access attempts, unusual data access patterns, and other potential security events.
- In the event of a suspected or confirmed security incident, we follow an internal incident response process to contain, investigate, and remediate the issue.
- Where a breach creates a real risk of significant harm to affected individuals, we will notify impacted users and the Office of the Privacy Commissioner of Canada in accordance with PIPEDA's breach-notification requirements, without undue delay.
11. Responsible Disclosure of Vulnerabilities
We welcome reports from security researchers and users who discover potential vulnerabilities in our Services.
- If you believe you have found a security vulnerability, please report it to info@aifarming.ca with sufficient detail for us to reproduce and assess the issue.
- Please do not publicly disclose a vulnerability before we have had a reasonable opportunity to investigate and address it.
- Please avoid accessing, modifying, or deleting data that does not belong to you, and do not perform any testing that could disrupt the availability of our Services for other users.
- We aim to acknowledge vulnerability reports promptly and will keep reporters informed of our progress toward a resolution where appropriate.
12. Third-Party Vendors and Service Providers
Where we rely on third-party vendors for hosting, payment processing, AI infrastructure, analytics, or other services, we take reasonable steps to select vendors with appropriate security practices and to include data-protection and confidentiality obligations in our agreements with them. However, we cannot guarantee the security practices of third parties, and each vendor is separately responsible for the security of systems under its own control.
13. User Responsibilities
Security is a shared responsibility. We encourage users to:
- Choose a strong, unique password for your AI Farming account and avoid reusing passwords from other services.
- Keep your login credentials confidential and never share your password with others.
- Log out of shared or public devices after use.
- Keep your device's operating system and the AI Farming app updated to the latest version.
- Notify us immediately at info@aifarming.ca if you suspect unauthorized access to your account.
14. Changes to This Security Policy
We may update this Security Policy from time to time to reflect changes in our security practices, infrastructure, or applicable legal requirements. Material changes will be communicated via email or a prominent notice on our website prior to taking effect. The "Last Updated" date at the top of this page indicates when the Policy was last revised.
15. Contact Us
If you have questions about our security practices, or wish to report a vulnerability or suspected incident, please contact:
AI Farming Canada
26 Winston Crescent, Whitby, Oshawa, ON, Canada
Email: info@aifarming.ca
Website: https://aifarming.ca
------------------------------------------------------------------------