Send us the details
Email security@agronome.ai with:
- A clear description of the vulnerability.
- Steps to reproduce, or a proof-of-concept payload.
- The impact you believe it has on customer data, accounts, or platform integrity.
- (Optional) Your name and any handle you'd like credited.
We don't currently offer a paid bug bounty, but we do publicly credit researchers (with your consent) for valid reports.
What you can expect from us
Within 1 business day
Acknowledgement that we received your report.
Within 5 business days
Our triage assessment — whether we've reproduced it, severity rating, and a target fix window.
Critical issues: within 7 days
Patch deployed to production for issues that risk customer data or account integrity.
Coordinated disclosure
We'll agree a public-disclosure date with you — typically after the fix ships, with credit to you if you'd like it.
What we ask in return
Good-faith research conducted in line with this policy is welcome. We won't pursue legal action against you for:
- Accessing only your own test account, or accounts you have explicit written permission to test.
- Avoiding actions that degrade service, exfiltrate other customers' data, or affect the integrity of farm records.
- Reporting privately to us before any public disclosure.
What's not in scope
- Denial-of-service or volumetric attacks.
- Social engineering of Agronome.ai employees, customers, or partners.
- Physical attacks against our offices or the offices of our cloud provider.
- Vulnerabilities in third-party services we use (please report those to the vendor directly).
- Reports generated solely by automated scanners without verification or impact analysis.
- Missing security headers without a demonstrated exploit.