Security and integrations
The data belongs to the farm. Protecting it is our job.
Where the data lives, how it is protected, who can access it and how upCampo connects with other systems. It's what IT asks before approving a vendor, answered here, in public.
Protection
What protects your farm data.
It applies to every farm, under any contract. It's not a separate package.
Encryption in transit and at rest
All access goes through HTTPS, with TLS 1.2 and 1.3, and the portal holds an A grade in a public check, repeated every month. At rest, data and backups are encrypted.
Each person sees what they need
Per-user permissions, screen by screen: view, create, edit or delete. The farm's own administrator is in control, with no need to go through upCampo.
An access log you can export
Who logged in, when, from where, on which screen and what they did. Kept for at least 180 days and exportable to Excel by the customer, ready for audit.
Access justification
The farm can require outside consultants and upCampo support to state a reason before logging in. The text is stored alongside the access record.
Automated monitoring
Every 15 minutes, the platform looks for warning signs, such as repeated failed password attempts or access from an unusual country, and raises an alert for review.
Continuous backup
Point-in-time recovery: data can be restored to its state at a specific time, not just to the last overnight copy.
Commitments
What the security policy defines.
- 1 hour
- maximum data loss in case of failure (RPO)
- 8 hours
- maximum time to bring the platform back (RTO)
- 24 hours
- to notify customers affected by an incident
- 180 days
- minimum access log retention
Targets from upCampo's Information Security Policy, version 1.0, approved in September 2026 and reviewed every year.
LGPD
The farm owns the data. upCampo processes it.
The contracting party is the controller
For the data your team enters, whoever contracts upCampo is the controller and upCampo is the processor: it handles the information only according to the customer's instructions. upCampo is the controller only of business contact data and of the records needed to keep the platform secure.
Used only to provide the service
It's in the contract: upCampo may not use the data for any purpose other than delivering the service. We don't sell, rent or share it.
End of contract
Before you leave, you export whatever you want through the reports, as spreadsheets. Afterward, the data is returned or deleted, with proof.
Appointed Data Protection Officer
upCampo has an appointed Data Protection Officer (DPO) and keeps the record of processing activities required by Article 37 of the LGPD (Brazil's data protection law). Contact details are in the privacy policy.
Integrations
The API is public, and so are the docs.
API documentation
REST API documented in an open standard: master data, crops, pest scouting reports, inventory, work orders, weather, cotton and fleet. Token authentication valid for 24 hours, bound to the company and the farm.
ERPs
Integration with Sankhya, Aliare (Siagri) and ViaSoft: the ERP pulls master data and transactions from upCampo and sends back its own code, linking both sides.
Machinery and weather
John Deere and Solinftec on the machinery side; Davis and Agrosystem weather stations on the weather side, with rainfall, temperature, humidity and wind.
Power BI
Direct connection to the data for your company dashboard, with no manual exports, putting crop information next to finance and sales.
Claude and ChatGPT
The UPí connector uses OAuth, respects each user's permissions and doesn't store the data it looks up: the answer goes to the assistant, where Claude's or ChatGPT's rules apply. The administrator can suspend AI access.
No server on the farm
The platform runs in the cloud. There's no server to install, maintain or back up at the office: all you need is a browser and the field app.
For your IT team
Documents available on request.
Ask on WhatsApp or by email at contato@upcampo.com.br. If your company has its own questionnaire, send it along: we'll fill it out.
Information Security Policy
Access control, encryption, logging and monitoring, vulnerabilities, backup and continuity.
Incident Response Plan
Classification, roles, steps and deadlines for containment and communication.
Record of processing activities
The document required by Article 37 of the LGPD: what data is processed, for what purpose, on what legal basis and for how long.
Customer security guide
In the Help Center: how to check who accessed the account, export the log and turn on access justification.
Security questionnaire
Where is upCampo data stored?
In the cloud, in data centers run by large providers, with encryption and continuous backup. The farm doesn't need its own server. The providers are disclosed to the customer's IT team during contracting, under confidentiality.
Is the data encrypted?
Yes, in transit and at rest. All access uses HTTPS, with TLS 1.2 or 1.3, and the portal holds an A grade in a public check of its HTTPS configuration, repeated every month. At rest, the database is encrypted, backups included.
How does upCampo's backup work?
Backup is automatic and continuous, with point-in-time recovery, and it is encrypted. The recovery point objective (RPO) is 1 hour, and the recovery time objective (RTO) is 8 hours. The policy calls for a restore test at least once a year, in a separate environment.
Who at upCampo has access to the data?
The technical team and support, under the principle of least privilege and each with their own user account — every access is recorded in the log the farm can view and export. Internal access is reviewed every three months, and access for anyone who leaves the company is revoked within 24 hours.
Can upCampo support access the farm's account without anyone knowing?
No. Every access is recorded in the log, which the farm itself can view and export. And, if the farm wants, it can require support and outside consultants to state the reason for access when logging in; the justification is stored alongside the access record.
How is access control handled for the farm's users?
By user and by screen, with separate view, create, edit and delete rights. Each farm has an administrator who adds, changes and removes access for their own team, with no need to go through upCampo. Users are unlimited, so there's no incentive to share logins.
Can one farm's data show up for another customer?
No. Each company's and farm's data is kept separate by permissions, and users only see the units their own company's administrator has linked them to. This also applies to answers from UPí.
Does upCampo have an audit trail?
Yes. The platform records who accessed it, when, on which screen, what operation they performed and whether it succeeded; the login record also stores the IP address and approximate location. Records are kept for at least 180 days, and the customer can view them and export to Excel from a portal screen, filtering by period, user or screen.
Does upCampo monitor suspicious access?
Yes. Every 15 minutes, an automated check scans the audit trail and raises an alert for repeated failed password attempts on the same user or access from a country outside the usual pattern of operation. Alerts are reviewed by the person responsible for security.
How does upCampo handle vulnerabilities?
With deadlines based on severity (CVSS), set in the policy: critical within 7 calendar days, high within 30, medium within 90 and low in the next scheduled release. Application dependencies are scanned automatically every three months, and a critical vulnerability under active exploitation is handled as an incident.
What happens if there is a security incident?
The Incident Response Plan kicks in: containment within 4 hours of detection, impact assessment within 12 hours and notice to affected customers within 24 hours for high- and medium-severity incidents, even if the investigation is still ongoing. When personal data is involved and there is significant risk to data subjects, the ANPD (Brazil's data protection authority) is notified under Article 48 of the LGPD, within 3 business days.
Is upCampo compliant with the LGPD?
Yes. upCampo acts as the processor of the data the customer enters into the platform and as the controller only of business contact data and security records. It has an appointed Data Protection Officer, whose contact details are in the privacy policy, and keeps the record of processing activities required by Article 37. Data subject requests are received by the Data Protection Officer and forwarded to the customer, as controller.
Does upCampo use farm data for other purposes or to train AI?
No. The contract prohibits using the data for any purpose other than providing the service. In the UPí connector for Claude and ChatGPT, each query is answered on the spot and the connector doesn't store the farm data: it goes only to the assistant the user connected, and what happens to the conversation from there (history, retention, use) follows Claude's or ChatGPT's rules and the user's account settings. upCampo does not use the data to train models.
What happens to the data at the end of the contract?
Before closing the account, the farm exports whatever it wants through the reports, as spreadsheets, without opening a ticket. Afterward, the data is returned or deleted, with proof, within the period set in the contract.
How is the upCampo API authenticated?
With a token valid for 24 hours, obtained with the company's integration credentials, with the company and the farm fixed in the token itself. All traffic is HTTPS. The full documentation is public, at suporte.upcampo.com.br/api.
How does security work for the AI connector (MCP)?
The connector uses OAuth and only reaches the farms the connected user already has access to. The password is checked at login and is never stored in the connector. Users can disconnect whenever they want, and the company administrator can suspend AI access in the user settings.
What documents does upCampo provide for vendor due diligence?
The Information Security Policy, the Incident Response Plan and the Record of personal data processing activities. If your company has its own questionnaire, send it along on WhatsApp or by email at contato@upcampo.com.br: we'll fill it out.
How do I report a suspected security issue to upCampo?
On WhatsApp at (65) 99937-3741 or by email at contato@upcampo.com.br. Suspected unauthorized access, a strange message sent in upCampo's name or a flaw you found: the sooner we know, the faster we act.
1 free month
IT signed off? Try it on the whole farm.
One free month across your whole farm, with no contract to sign. The month starts at onboarding. Leave your name, WhatsApp and farm size: we'll reach out to set up the farm with you.