Approved in a security due diligence: how upCampo protects farm data
upCampo passed the information security assessment of a multinational agribusiness company, scoring 92 with low criticality. What was assessed and what it means for the farm.
By upCampo
upCampo was approved in the information security assessment of a multinational agribusiness client, with a score of 92 (148 out of 160 points) and low criticality. This kind of assessment, also called a security due diligence, is what large companies run before hiring software: the IT team checks how data is protected, who has access, what gets logged and what happens when something goes wrong. This article explains what such an assessment checks, what upCampo presented and what it means for anyone who trusts the system with farm data, whether a group with its own IT department or a grower who just wants to know the information is safe.
The result, in numbers
| Item | Result |
|---|---|
| Final score | 92 |
| Points | 148 out of 160 |
| Criticality | low |
| Decision | approved |
The client’s name is not disclosed. The assessment followed the company’s own questionnaire and criteria, not a certification: it shows that, reviewed by a multinational-sized security team, upCampo meets what that team requires from a vendor that holds operational data.
Is farm management software secure?
It depends on the vendor, and it can be checked. Farm management software stores work orders, inventory, cost per field, production and contracts: strategic information that matters to competitors, buyers and suppliers. Secure software protects that data on four points: encryption, control over who has access, a log of everything that was done and the ability to recover data after a failure. The right question for any vendor is whether they answer this in writing, and whether the client can verify part of the answers without depending on them.
upCampo answers in public: the full security questionnaire is on the security and integrations page.
What does a security due diligence of farm software assess?
A security due diligence checks whether the vendor has controls to protect client data and whether those controls work in practice, not just on paper. Questionnaires vary from company to company, but they usually cover the same blocks:
- Data protection: encryption in transit and at rest.
- Access control: who gets in, with which permission, and how access is reviewed.
- Logging and monitoring: whether every access is recorded and whether suspicious behavior triggers alerts.
- Backup and continuity: how much data can be lost in a failure and how long the system takes to come back.
- Incident response: what the vendor does, and how quickly it notifies the client.
- Data protection law (LGPD): each party’s role in processing the data, a named data protection officer and what happens at the end of the contract.
- Documentation: security policy, incident response plan and record of processing activities.
For large farming groups, this step has become a normal part of buying software. The IT department is usually who stalls the purchase when it can’t find answers.
How does upCampo protect farm data?
With encryption in transit and at rest, per-user permissions, a log of every access, automated monitoring and continuous backup. That is what was presented in the assessment, and it applies to every farm under any contract; it is not a separate package.
- Data is encrypted in transit and in storage, including backups.
- Each person sees only what they need, screen by screen: view, add, edit or delete, set by the farm’s own administrator.
- Every access is logged, and the client can view and export the history in the portal.
- Automated monitoring of security events, such as repeated failed password attempts.
- Continuous backup, with point-in-time restore: data can be returned to its state at a specific time, not just to the last copy.
- Incident response plan, with client notification within 24 hours.
On upCampo’s side, internal access is reviewed every quarter, and anyone who leaves the company loses access within 24 hours.
Who can access my farm’s data, and how can I see it?
Whoever the farm’s administrator authorized, with the permission they set, and every access goes into a log the client can view. The log shows who logged in, when, on which screen and what they did; it is kept for at least 180 days and can be exported to a spreadsheet, ready for audit.
This also applies to upCampo’s support team: each person logs in with their own user, and the access appears in the same log. When the company requires it, the farm can make support staff and outside consultants state a reason before logging in, and the justification is saved together with the access.
The step-by-step for checking who accessed and enabling access justification is in the Help Center security guide (in Portuguese).
What happens if there is a security incident?
upCampo triggers its Incident Response Plan and notifies affected clients within 24 hours, even if the investigation is not over yet. The plan sets containment within 4 hours of detection and impact assessment within 12 hours. When personal data is involved and there is relevant risk to people, Brazil’s data protection authority (ANPD) is notified, as the LGPD requires.
For failures that are not attacks, such as an infrastructure problem, the security policy targets are at most 1 hour of lost data and 8 hours for the platform to come back.
Does upCampo comply with the LGPD?
Yes. For the data the farm team enters, whoever hires upCampo is the controller, and upCampo is the processor: it handles the information only to provide the service, without selling, renting or sharing it. upCampo has a named Data Protection Officer and keeps the record of processing activities required by law. At the end of the contract, the client exports whatever they want through the reports and, afterwards, the data is returned or deleted, with proof. Details are in the privacy policy.
What this means if you are not a multinational
A farm without an IT department gets exactly the same protection that was assessed. There is no “large company” version of security: encryption, access logs, backup and the incident plan apply to every contract.
For companies with an IT department, the path is shorter: the Information Security Policy, the Incident Response Plan and the Record of Processing Activities are sent on request, and the team answers the company’s own questionnaire. Groups with several farms will find the rest of what they usually ask for, such as per-unit permissions and Power BI integration, on the large and medium farms page.
Security is not an extra feature. It is the basics of taking care of your farm’s data.
Frequently asked questions
What score did upCampo get in the security assessment?
A score of 92, with 148 out of 160 points, low criticality and an approval decision. The assessment was carried out by a multinational agribusiness client, using the company’s own questionnaire and criteria.
What is an information security due diligence?
It is the assessment a company makes of a vendor before trusting it with data. The IT team checks encryption, access control, logging, backup, incident response and data protection compliance, and decides whether the risk is acceptable.
Is upCampo’s farm management software secure?
Yes. Data is encrypted in transit and at rest, each user sees only what the administrator allowed, every access is logged, and there is automated monitoring and continuous backup. These controls were approved in a multinational client’s assessment, and the full questionnaire is on the site’s security page.
Can the upCampo team see my farm’s data without my knowing?
No. Each team member logs in with their own user, and every access goes into the log the farm views and exports. The farm can also require support staff to state a reason before logging in.
Where is upCampo’s data stored?
In the cloud, with large-scale providers, with encryption and continuous backup. The farm doesn’t need its own server. The providers are disclosed to the client’s IT department during contracting, under confidentiality.
Does upCampo use farm data to train artificial intelligence?
No. The contract prohibits using the data for any purpose other than providing the service, and that includes training AI models.
Does upCampo send documents for my company’s vendor assessment?
Yes. The Information Security Policy, the Incident Response Plan and the Record of Processing Activities are sent on request, via WhatsApp or by email at contato@upcampo.com.br. If the company has its own questionnaire, the team answers it.


