Reporting a security vulnerability
How to report
Email security@agrolog.com, in English or Danish. Please include:
the product or service affected, and the version or device ID if you know it;
what the problem is and what an attacker could do with it;
the steps needed to reproduce it.
What we will do
Acknowledge your report within 3 working days.
Give you our initial assessment within 10 working days.
Keep you informed while we investigate and fix.
Credit you when we publish the fix, unless you prefer otherwise.
What we ask
Give us reasonable time to fix the problem before you publish — we aim for 90 days, and will tell you if a fix needs longer.
Test only against your own account and your own devices.
Do not access, change or delete data belonging to our customers.
Do not degrade our services or our customers' installations.
Good-faith research
We will not take legal action against anyone who reports in good faith and follows this policy.
Scope
In scope: AgroLog Manager and its cloud services, the AgroLog App and Farmer platform, AgroLog Insight, AgroLog Gateway, Netlink and Netcontroller, the Wireless Sensor Spear (CSS / CSS-TM), and C-PRO moisture meters.
Out of scope: automated scanner output without a demonstrated impact, missing HTTP headers or email-configuration findings on this marketing website, denial-of-service testing, social engineering of our staff or customers, and physical attacks.
Rewards
We do not run a paid bug-bounty programme. We do give public credit, and our thanks.
Security advisories
When we fix a vulnerability that affects customers, we publish an advisory here with the affected products, the fix, and what you need to do.
Machine-readable contact details: security.txt

