Field Enterprise · Specifications
What an enterprise deployment is.
The environment, the controls, the data terms, the service levels and the services, written for your IT, security and procurement teams to read without a call. Every line here is in our Enterprise Technical Specifications, shared in full under NDA.
01 · Environment
A private instance.
A dedicated, isolated deployment: your own database instance, your own storage under a customer-specific encryption key, a dedicated access role limited to your resources, dedicated compute with a guaranteed allocation, a dedicated vector store and a dedicated backup vault. No database processes, memory or storage shared with another customer.
Managed by Aydi on AWS in eu-west-1 (Ireland). We handle security, patching, backups and monitoring.
Data locked to another region (EU-only, APAC, US) is planned for Q4 2026, under an enterprise contract.
02 · Security
The controls your security team already audits.
ISO 27001:2022 and ISO 27701:2019 certified, verified annually by an accredited certifying body.
Encryption at rest with AES-256 and in transit with TLS. Encryption context enforces tenant isolation at the cryptographic layer; enterprise customers have their own key.
Web application firewall, DDoS protection and least-privilege access. Threat detection, security posture monitoring and immutable audit logging run continuously.
Automated vulnerability scans on every code deployment. An independent penetration test every year, covering the web application, APIs, AI inference endpoints, cloud infrastructure and isolation between customers. The executive summary is available to enterprise clients under NDA.
Isolation is tested on every deployment: a test tenant attempts to reach another tenant's data through every endpoint, and the attempt must fail.
03 · Access to your data
Nobody has standing access.
No engineer has standing access to your content. Access happens only to fix an issue you have reported or to respond to a security incident.
Every such access requires multi-factor authentication, is logged immutably and is reviewed quarterly.
Within ORTH, access is per named user, with admin, agronomist and viewer roles set by your administrators.
04 · AI providers and your data
Trains no shared models.
The model providers ORTH uses do not train on the data ORTH sends them, under their commercial terms.
Personal data and farm identifiers are stripped from every prompt before it leaves our servers, so the payload a provider receives contains neither.
Provider log retention: seven days at the shortest, thirty days at most, for abuse monitoring only.
Your protocols and your fields' data train no shared models.
05 · Availability and support
Service levels.
99.9% monthly uptime, which is at most 44 minutes of downtime a month. Maintenance with at least 24 hours' notice, excluded from the uptime calculation.
Zero data loss as a hard commitment: multi-AZ database with automatic failover, point-in-time recovery to any second in the last 35 days, versioned storage and immutable backups that nobody, including our own administrators, can delete.
Recovery objectives: one hour for data, four hours for service.
Support: critical issues (platform down or a data-loss event) get a response within one hour and resolution within six; high priority within three hours and twenty-four; medium within six hours and seventy-two.
Any confirmed security incident affecting your data is notified within 24 hours.
Support by level. Enterprise: standard support. Enterprise Plus: a named customer success manager with a quarterly review. Strategic Partner: a dedicated success team with an executive sponsor.
06 · When it ends
Your data leaves with you.
Enterprise contract: an offboarding call within five business days, a full data export within twenty business days, deletion of every copy within thirty days of your export confirmation, and a signed Data Destruction Certificate within sixty days covering database, files, AI history and backups.
Subscription plans: access is disabled on cancellation, with a thirty-day grace period to export or reactivate. On day thirty your data is deleted; by day sixty every backup copy has expired, and you receive a deletion confirmation.
07 · Implementation and services
From signature to the field.
Validation first: your senior agronomists score ORTH against your own standards, on your crops and your cases, and rollout proceeds on the threshold your panel sets.
Virtual implementation, per site: four sessions of two hours over two weeks, remote. Your plots and data set up, your team trained.
Physical implementation, per site: three days on your farm, local or intercontinental. Set-up and training with your team, on site.
Review and enablement sessions, and training or use-case development sessions, of two hours each.
Solution architecture when the deployment needs two or three systems integrations; each systems integration quoted per system. Additional sites and services are charged as delivered, against your commitment.
08 · Devices and languages
Built for the phone in the field.
iOS, Android and web. Usable offline in the field.
Conversational in any language; interface in Spanish, Portuguese and English.
Built for the mid-range Android devices most growers already carry. A smartphone is the only hardware requirement.
09 · Scope
What ORTH is not.
Not an ERP, a labour-management system, a machinery or irrigation controller, or a quality-management system at the line. ORTH works alongside them.
Not lab-grade nutrient quantification. ORTH recommends soil and tissue tests, and interprets the results.
Not a compliance certifier. ORTH enforces your approved lists and flags residue limits, pre-harvest intervals and registered inputs; the sign-off stays with your people.
Questions your security review needs answered that are not here? Write to dpo@aydi.com. We answer enterprise security questions within two business days.