Taranis Data Security and Retention

Taranis Data Security and Retention

Data Security


Introduction


Taranis is committed to providing its customers with a highly secure and reliable environment for our data operations and cloud-based applications. We have therefore developed a multi-tiered security model that covers all aspects of hosted and cloud-based Taranis systems. The security model and controls are based on international protocols and standards and industry best practices.


As part of the company’s focus on security issues, Taranis employs security-oriented management staff including a Chief Technology Officer, a VP R&D and a Chief Innovation Officer as well as cloud platform and data & services team with responsibility for:


  • Applying the security model to all system tiers

  • Monitoring and analyzing the infrastructure for suspicious activities and potential threats

  • Issuing security reports to Taranis management 

  • Dynamically updating the security model and addressing new security threats


In addition, a Taranis joint committee, including representatives from product management and R&D is committed to:


  • Systematically examining the organization's information security risks, considering threats and vulnerabilities

  • Designing and implementing a coherent and comprehensive suite of information security controls and/or other forms of risk treatment (such as risk avoidance or risk transfer) to address the risks that are deemed unacceptable

  • Adopting an overarching management process to ensure that the information security controls continue to meet the organization's evolving information security needs


Taranis utilizes private storage “buckets” in the Google  Cloud Platform. Additional Google Cloud security, privacy and compliance policies can be found here:


Operational and Information Security 

Taranis has implemented a strict set of procedures throughout the entire data life-cycle, to ensure all captured data is security processed, stored and made available only to authorized users. These include:

  • Drones or planes taking images in the field based or precalculated routes, and the captured imagery is stored only on a local memory card.

  • At the end of the flight, the certified pilot uploads the images using a Taranis provided laptop as well as using a secured Taranis-developed application.

  • The data is uploaded into predefined, Taranis owned, private buckets in the Google Cloud Platform (GCP).

  • Stored data in the Google Cloud Platform can be accessed only via a dedicated secured service and made available to customers using the Taranis web and mobile interface based on individual user permissions.


Application Security

The following items are relevant for the application access control:

  • Access control – Access to the Google Cloud Platform buckets is limited, based on role and responsibility and is only available to permitted users for maintaining and supporting customers

  • Authentication – Taranis also enforces a Google based multi-factor authentication including a strict role-based password policy. For Taranis web and mobile apps, user passwords are stored in an encrypted form, using a one-way encryption method based on an industry-standard hash algorithm. Only the application is able to compare the hashed and entered passwords. 

  • Data encryption: based on the Google Cloud platform, it encrypts data in transit between our facilities and at rest, ensuring that it can only be accessed by authorized roles and services with audited access to the encryption keys. Additional details provided below.


Data Encryption at Rest

Taranis uses the Google Cloud Platform for storage. 

  • Google Cloud encrypts all customer content stored at rest, without any action from the customer, using one or more encryption mechanisms.

  • Google Cloud encrypts all customer content stored at rest, without any action required from the customer, using one or more encryption mechanisms.

  • Data for storage is split into chunks, and each chunk is encrypted with a unique data encryption key. These data encryption keys are stored with the data, encrypted with ("wrapped" by) key encryption keys that are exclusively stored and used inside Google's central Key Management Service. Google's Key Management Service is redundant and globally distributed.

  • All data stored in Google Cloud is encrypted at the storage level using AES256, with the exception of a small number of Persistent Disks created before 2015 that use AES128.

  • Google uses a common cryptographic library, Tink, which incorporates our FIPS 140-2 Level 1 validated module, BoringCrypto, to implement encryption consistently across almost all Google Cloud products. Consistent use of a common library means that only a small team of cryptographers needs to implement and maintain this tightly controlled and reviewed code.

Detailed information can be found here: https://cloud.google.com/docs/security/encryption/default-encryption 


Data Encryption at Transit

  • Google employs several security measures to help ensure the authenticity, integrity, and privacy of data in transit.

  • Google encrypts and authenticates data in transit at one or more network layers when data moves outside physical boundaries not controlled by Google or on behalf of Google. All VM-to-VM traffic within a VPC network and peered VPC networks is encrypted.

  • Google applies default protections to data in transit. For example, we secure communications between the user and the Google Front End (GFE) using TLS.

  • Detailed information can be found here: https://cloud.google.com/docs/security/encryption-in-transit 


Taranis Records Retention Policy

Purpose and Scope

Taranis is committed to protecting our systems, information, and our customers’ information.

This policy defines Taranis's retention and disposal requirements for customer-related data collected, received, or generated in connection with the Taranis services.

The policy applies to electronic and physical records containing customer data and to Taranis employees and contractors who access or manage such data.

Responsibilities

Taranis Employees and Contractors who create or use records must maintain them according to this policy.

Taranis Management at all levels are responsible for ensuring compliance within their teams.

Data Categories

User-Provided / Generated Data includes information supplied by or on behalf of a user or customer, including user profile information, grower, farm and field information, field boundaries, notes, other user-uploaded data and user activity logs or through customer-provided data integrations (e.g. John Deere Operations Center, or customer internal databases, systems or datalakes, etc).

Taranis Generated Data includes information generated or acquired by Taranis in connection with providing the services, including drone imagery, 3rd party acquired data (e.g. satellite imagery, soil, weather), and derived data from these sources such as insights, layers and recommendations and similar outputs associated with a customer, grower, farm, field, or user.

Anonymized, Aggregated or De-identified Data means information that has been anonymized, aggregated or de-identified such that it no longer identifies a customer or individual. Non-anonymized data will be referred to as individual-identifiable data.

Retention Requirements

Taranis retains User-Provided Data and Taranis Generated Data for the duration of the applicable customer agreement in order to provide the services and preserve historical information and functionality for customers.

Following termination or expiration of the applicable customer agreement, User-Provided Data will be either retained or deleted and individual-identifiable Taranis Generated Data will either be anonymized or deleted as per the schedule defined in the customer agreement, unless:
  1. Retention is required by law or legal hold, or
  2. The underlying client (grower) continues Taranis service under a new agreement. In this case, client-specific data required to maintain service will be transferred to the new account and retained according to the new agreement, provided the transfer is not prohibited by the original contract.
Acquired 3rd party data may be deleted according to applicable licensing requirements and Taranis operational practices. Taranis currently retains applicable satellite imagery for approximately three years.

Images, Anonymous Information or aggregated and de-identified data (as defined in the customer agreement) that no longer identifies the customer or any individual may be retained by Taranis indefinitely for internal analytics, product improvement, research, AI/model development, and other legitimate business purposes.

Customer-Specific Requirements

Where a customer contract or approved customer records-retention schedule specifies different retention requirements, those requirements will apply to that customer's data.

Disposal

At the end of the applicable retention period, Taranis will delete, anonymize, or otherwise securely dispose of the affected data in accordance with its technical and operational processes.

Where contractually required, Taranis can provide written confirmation that applicable customer data has been deleted.

Data contained in backup systems may remain until overwritten or expired through the applicable backup lifecycle, provided that such data remains protected and is not restored except for disaster recovery or business continuity purposes.

Exceptions

Retention and deletion may be suspended where necessary to comply with applicable law, legal process, litigation hold, regulatory requirement, or other binding obligation.

Responsibility

The Taranis Vice President of R & D is responsible for ensuring compliance with this policy and will assist with the protection of Taranis data.