Security is foundational to how CactusCo is built — from encrypted sensor telemetry to on-site deployment options that keep your operational data under your control.
CactusCo's platform runs across sensor networks, drip controllers, and farm operations that our customers depend on every growing season. We treat the confidentiality, integrity, and availability of that data as a core product requirement, not an afterthought.
Layered controls across network, application, and data levels, so no single safeguard is a single point of failure.
Employees and systems get access to only the data and infrastructure required for their function.
Automated alerting on infrastructure, sensor gateways, and application layers around the clock.
On-site deployment options mean farm data can stay on your network by default.
Our cloud infrastructure is hosted with reputable providers operating data centres in Canada and the United States, selected for their independently audited physical and environmental controls.
Data is encrypted both in transit and at rest throughout the CactusCo platform.
| Layer | Protection |
|---|---|
| In transit | TLS 1.2+ for all traffic between sensors, gateways, applications, and our servers |
| At rest | AES-256 encryption for stored telemetry, farm records, and backups |
| Key management | Managed key-rotation policies with restricted, audited access to encryption keys |
| Credentials | Passwords are hashed with a modern salted algorithm; we never store credentials in plain text |
Access to customer environments and internal systems is governed by role-based permissions and reviewed on a regular basis.
For operations that require data to stay on local infrastructure, CactusCo supports on-site deployment of the full platform on your own network.
In this configuration, sensor telemetry, irrigation logs, and yield records remain on your premises by default. No farm data leaves your installation without your explicit permission — for example, if you choose to enable optional cloud analytics or remote support.
Field hardware is a common attack surface for agricultural technology, so we apply specific safeguards to sensors, gateways, and drip controllers:
We maintain continuous monitoring across infrastructure, applications, and sensor gateways, with automated alerting for anomalous activity.
In the event of a confirmed security incident affecting customer data, we follow a documented response process: containment, investigation, remediation, and timely notification to affected customers in accordance with applicable law, including PIPEDA and Québec's Law 25.
We welcome reports from security researchers and take all credible reports seriously.
Our practices are designed to support customers operating under Canadian privacy law, including PIPEDA and Québec's Law 25, and to align with common industry security frameworks as our platform scales. See our Privacy Policy for details on how we handle personal information.
We use a limited number of vetted sub-processors for hosting, backups, and communications — each bound by contractual data protection obligations. A current list is available on request.
Questions about our security practices, or reporting a vulnerability:
security@cactusco.exampleOur team is happy to walk through our architecture, on-site deployment options, or a specific compliance requirement.