Reporting a security vulnerability

How to report

Email security@agrolog.com, in English or Danish. Please include:

  • the product or service affected, and the version or device ID if you know it;

  • what the problem is and what an attacker could do with it;

  • the steps needed to reproduce it.

What we will do

  • Acknowledge your report within 3 working days.

  • Give you our initial assessment within 10 working days.

  • Keep you informed while we investigate and fix.

  • Credit you when we publish the fix, unless you prefer otherwise.

What we ask

  • Give us reasonable time to fix the problem before you publish — we aim for 90 days, and will tell you if a fix needs longer.

  • Test only against your own account and your own devices.

  • Do not access, change or delete data belonging to our customers.

  • Do not degrade our services or our customers' installations.

Good-faith research

We will not take legal action against anyone who reports in good faith and follows this policy.

Scope

In scope: AgroLog Manager and its cloud services, the AgroLog App and Farmer platform, AgroLog Insight, AgroLog Gateway, Netlink and Netcontroller, the Wireless Sensor Spear (CSS / CSS-TM), and C-PRO moisture meters.

Out of scope: automated scanner output without a demonstrated impact, missing HTTP headers or email-configuration findings on this marketing website, denial-of-service testing, social engineering of our staff or customers, and physical attacks.

Rewards

We do not run a paid bug-bounty programme. We do give public credit, and our thanks.

Security advisories

When we fix a vulnerability that affects customers, we publish an advisory here with the affected products, the fix, and what you need to do.



Machine-readable contact details: security.txt