Back to Security & Trust

Responsible disclosure

If you've found a security issue in Agronome.ai, we want to hear about it. Here's how we work with you.

How to report

Send us the details

Email security@agronome.ai with:

  • A clear description of the vulnerability.
  • Steps to reproduce, or a proof-of-concept payload.
  • The impact you believe it has on customer data, accounts, or platform integrity.
  • (Optional) Your name and any handle you'd like credited.

We don't currently offer a paid bug bounty, but we do publicly credit researchers (with your consent) for valid reports.

Response timeline

What you can expect from us

Within 1 business day

Acknowledgement that we received your report.

Within 5 business days

Our triage assessment — whether we've reproduced it, severity rating, and a target fix window.

Critical issues: within 7 days

Patch deployed to production for issues that risk customer data or account integrity.

Coordinated disclosure

We'll agree a public-disclosure date with you — typically after the fix ships, with credit to you if you'd like it.

Safe harbour

What we ask in return

Good-faith research conducted in line with this policy is welcome. We won't pursue legal action against you for:

  • Accessing only your own test account, or accounts you have explicit written permission to test.
  • Avoiding actions that degrade service, exfiltrate other customers' data, or affect the integrity of farm records.
  • Reporting privately to us before any public disclosure.

What's not in scope

  • Denial-of-service or volumetric attacks.
  • Social engineering of Agronome.ai employees, customers, or partners.
  • Physical attacks against our offices or the offices of our cloud provider.
  • Vulnerabilities in third-party services we use (please report those to the vendor directly).
  • Reports generated solely by automated scanners without verification or impact analysis.
  • Missing security headers without a demonstrated exploit.