Skip to content
Mutus Tech

Trust

How we handle data, security and compliance.

Everything a procurement officer, programme funder or potential pilot partner would want to know on day one — in plain language, with honest status flags.

Data handling

What we collect, where it goes, who sees it.

  • What we collect from you

    Field boundary data (GeoJSON / KML), soil chemistry results, crop and rotation history, target yields, weather observations, applied input records, and any photos / notes you choose to attach to records. We collect what you give us — no shadow telemetry.

  • Why we collect it

    To produce field-level fertilisation plans, NDVI overlays, Farm Tasks and partner-ready evidence packs as described under your engagement agreement. Nothing else.

  • Where it's stored

    Production data is held on infrastructure in the UK and EU (Cloudflare, AWS eu-west). Backups are encrypted at rest. Connection-level traffic is encrypted via TLS 1.3 in transit. We do not send your field data to third-party AI providers.

  • Who can see it

    Your team and any advisers you invite. Mutus Tech staff with operational access (for support, debugging and platform improvement) — minimum necessary, audited. Never sold, never shared with advertisers or data brokers. Subprocessor list available on request under your engagement agreement.

  • Data you own

    Your field data, soil test results, plan inputs and applied input records remain your data. You can export them at any time, and we will return or delete them on exit per the engagement terms.

  • Anonymised aggregates

    We retain the right to use anonymised, aggregated learnings (e.g. average N rates by crop and region) to improve the platform and contribute to peer-reviewed research. Individual fields and farms are never identifiable in these aggregates.

Security posture

Where we stand, where we're heading.

We use honest status flags rather than "Certified ✓" badges. The roadmap below is what a procurement reviewer would actually want to evaluate.

Control Status Note
Transport encryption In place TLS 1.3 enforced; HSTS preload candidate.
At-rest encryption In place Database and backup volumes encrypted using provider-managed keys.
Multi-factor auth (staff) In place Required for all production access; hardware-key preferred.
Cyber Essentials Targeting 2026 Standard UK government baseline — application in preparation.
Cyber Essentials Plus Planned Annual independent audit; targeted after stable production rollout.
ISO 27001 Considering Roadmap depends on enterprise / public-sector contract requirements.
Penetration testing Annual External pen-test on the platform; report available under NDA.
Vulnerability disclosure Open security@mutus.co.uk — responsible disclosure welcomed; we aim to acknowledge within 3 working days.

Compliance & governance

The standards we operate under.

  • UK GDPR & Data Protection Act 2018

    We process personal data as a controller in respect of our own users and as a processor where farm data is held on behalf of partners. Lawful basis: contract performance and legitimate interest. Subject rights honoured; requests via contact@mutus.co.uk.

  • PECR / cookies

    This website does not set tracking cookies. No third-party analytics is loaded. The contact form uses Cloudflare Turnstile (no cookies). If we add analytics in future, we will declare it here and add a clear cookie banner first.

  • Companies House registration

    Mutus Tech Ltd — company number 13274475 — UK private limited company since 2021. Registered office: 54 St James Street, Liverpool L1 0AB.

  • Accessibility

    We aim to meet WCAG 2.1 AA across this website and the platform. See our accessibility statement for the current state, known issues and how to report problems.

Reporting issues

How to raise a concern.

Security disclosure

Found a vulnerability? Email contact@mutus.co.uk with subject "Security disclosure". We acknowledge within 3 working days.

Data request (GDPR)

Subject access, correction, deletion: contact@mutus.co.uk. We respond within one calendar month.

Accessibility issue

If something on this site is hard to use, email contact@mutus.co.uk. We aim to acknowledge within 5 working days.

This page is reviewed at least quarterly. Last reviewed: 23 May 2026.

Policies: Data Security · Data Sharing · Data Management · Website Privacy · Pezego App Privacy · Accessibility