Vulnerability Disclosure Policy
At Agrismart, security is a top priority, and we are committed to maintaining the privacy and security of our systems and customers. This Vulnerability Disclosure Policy outlines how security researchers can report vulnerabilities in a responsible manner and what to expect from us in response.
1. Reporting Security Vulnerabilities
If you discover a potential security vulnerability on any of our services, we encourage you to let us know as soon as possible. We welcome collaboration from the security community to help us maintain the security and privacy of our users.
How to Report:
- Please email your findings to [email protected].
- Provide a detailed description of the vulnerability and the steps needed to reproduce it.
- If possible, include any proof-of-concept code, screenshots, or logs that would help us understand the issue.
2. Scope
The following areas of our services are in-scope for vulnerability reporting:
- Websites and web applications hosted under agrismart.co.nz, agrismart.com and any subdomains..
- Mobile applications for iOS and Android developed by Agrismart.
- APIs and backend services provided by Agrismart.
The following are out-of-scope:
- Denial of service attacks.
- Spamming, phishing, or social engineering attacks.
- Physical security vulnerabilities.
- Vulnerabilities requiring significant social engineering, such as convincing users to install malicious software.
3. Our Commitment
We commit to the following:
- Acknowledge your report within 3 business days.
- Investigate and respond with our initial findings within 10 business days. We may request further information to help verify or reproduce the issue.
- Remediate valid vulnerabilities as soon as possible, depending on severity and impact.
4. Safe Harbour
We will not take legal action against individuals who:
- Make a good faith effort to comply with this Vulnerability Disclosure Policy.
- Report the vulnerability to us without making it public before we have had a reasonable time to address the issue.
- Do not exploit the vulnerability for personal gain or to harm others.
5. Rewards
At this time, we do not offer monetary rewards (bug bounties) for vulnerability disclosures. However, we recognize and appreciate the efforts of security researchers who contribute to the security of our services.
6. Exclusions
While researching, please refrain from:
- Performing actions that could negatively impact the reliability or integrity of our systems (e.g., DoS attacks).
- Attempting to gain access to another user's data without consent.
- Publicly disclosing the vulnerability prior to our resolution.
Thank you for helping us keep Agrismart secure!