Trust & security

Security

How HydroIQ, LLC protects your garden, your data, and the network. HydroIQ is pre-launch; some capabilities described below — including camera and cloud-analytics features — are planned and not yet available.

Last updated: 12 May 2026

Four architectural rules

These are foundational design principles, built into the system architecture rather than left to policy.

  1. Video is not recorded. When camera features become available, live video is intended to be relayed for viewing only, not written to our infrastructure for storage.
  2. AI images deleted after analysis (planned feature). When camera plant-health analysis ships, camera stills will exist in memory only during the analysis call. The analysis result will be kept; the image bytes will not.
  3. Local-first by default. Schedules run on the device. Cloud is for intelligence, not control.
  4. Append-only audit log. Actions such as valve operations, fertigation doses, and control commands are recorded in an append-only log designed to prevent later modification.

Encryption

  • All connections between the controller, cloud, and app are encrypted in transit using TLS 1.2 or higher.
  • Firmware updates are cryptographically signed, and the device verifies each update's signature before installation. Updates that fail verification are not installed.
  • When camera live-view becomes available, sessions will require time-bound session tokens that expire automatically.
  • Account passwords are protected using industry-standard salted hashing; we do not store passwords in plaintext.

Data minimization

  • Garden GPS coordinates are reduced at the device to a coarse, neighborhood-level resolution before transmission. Exact coordinates stay on the device.
  • Camera live streams (when offered) are relayed only — never written to disk on our infrastructure.
  • If and when cloud plant-health analysis becomes available, camera stills are processed transiently for that analysis and are not retained afterward.
  • Telemetry retention: raw sensor data is retained for 60 months (5 years); aggregated averages are retained for longer periods, with the longest-horizon aggregates retained indefinitely and owner-deletable. See the Privacy Policy for the full retention table.

Security incident notification

If we become aware of a security incident affecting your personal data, we will notify affected customers and, where required, the relevant regulators without undue delay and in accordance with applicable law.

Responsible disclosure

If you find a vulnerability in HydroIQ hardware, firmware, cloud, or app, please email security@hydroiq.us. We commit to:

  • Acknowledge your report promptly, typically within a few business days.
  • Provide an initial triage decision within 10 business days.
  • Coordinate a fix and public disclosure within 90 days of acknowledgment, longer only by mutual agreement.
  • Credit you in the disclosure unless you prefer to remain anonymous.
  • Not pursue legal action against good-faith researchers who follow this process, and consider such testing authorized under the Computer Fraud and Abuse Act and analogous state and federal laws, provided you act in good faith, do not access or modify data belonging to other users, do not degrade or disrupt the service, and do not publicly disclose the issue before we have coordinated a fix.
  • We do not currently operate a paid bug-bounty program; reports are handled on a recognition basis, and we credit reporters in the disclosure as described above.

security.txt

Our security.txt file lists the security contact, encryption key, and policy URL in the format described by RFC 9116.

Public CVE register

Vulnerabilities we publicly disclose will be listed in a public security advisory register, which we expect to publish as the product reaches general availability. Beta-period security advisories are sent to active beta participants by email.

For procurement & IT teams

If your organization needs a security review packet (such as an architecture and data-flow overview, an encryption-in-transit / at-rest summary, and a vendor questionnaire response), email security@hydroiq.us with your organization name and the procurement contact, and we will respond promptly with a packet.

← Back to HydroIQ