Vulnerability Disclosure Policy

Effective Date: 01 October 2005
Modified Date: 15 February 2025

For Previous Versions of this policy, Click here

Our purpose is to provide exceptional agricultural services while maintaining the highest standards of security and trust. The protection of information entrusted to us by our clients, partners, and stakeholders is fundamental to our operations. This policy outlines our approach to handling potential security vulnerabilities and establishes guidelines for their responsible disclosure to the company.

1. Introduction

1.1 Our purpose is to provide exceptional agricultural services to our clients and make a difference in farming communities, and we can’t do that without trust. Central to maintaining this trust is the protection of the information that we’ve been entrusted with by our clients, customers, partners, and stakeholders. This policy outlines considerations and commitments for the disclosure of potential security vulnerabilities to the company in a responsible manner.

2. Security Researchers

2.1 The company recognises the positive contributions of security researchers and encourages the responsible and direct disclosure of potential security vulnerabilities to us. We accept vulnerability reports from all sources.

3. Our Commitments to Researchers

3.1 We will maintain standard confidentiality in our communications with you.

3.2 We will work with you to validate and respond to your disclosure.

3.3 We will investigate and use all reasonable efforts to remediate validated issues in a manner consistent with protecting the safety and security of those potentially affected by a reported vulnerability.

3.4 The Company reserves all of its legal rights in the event of noncompliance with this Policy, but it does not intend to pursue legal action against any party that conducts security research and discloses information to us in good faith and as outlined in this Policy.

4. What We Ask of Researchers

4.1 We request that you communicate information about potential security vulnerabilities in a responsible manner. This means complying with all applicable laws and respecting the privacy of individuals. Your security research should also avoid the degradation of our users’ experiences, disruption to systems, and destruction of data.

4.2 We request that researchers provide sufficient technical detail and background necessary for our team to identify and validate reported issues, using the contact methods provided below.

4.3 We request that researchers act for the common good, protecting user privacy and security by refraining from publicly disclosing vulnerabilities.

5. Scope

5.1 The company defines a security vulnerability as an unintended weakness or exposure that could be used to compromise the integrity, availability, or confidentiality of our digital assets. This policy applies to all digital assets owned, operated, or maintained by the company, including applications, systems, public-facing websites, and our agricultural services.

5.2 While many view our Company as simply “A Chowns Agricultural Services,” we operate through multiple channels, including our contracting partners and service providers who assist in delivering agricultural services to our customers. It is especially important that researchers understand the ownership of digital assets that are the targets of their research because of our close partnerships with other companies who may conduct business using the company name but are not within the scope of this policy.

5.3 No part of this policy should be understood to authorize research on behalf of any third-party to the company.

6. Out-of-Scope Activities

6.1 The following activities are explicitly out of the scope of this policy:

  • Compromising the integrity, availability, or confidentiality of non-public information in the possession of the company.
  • Failing to delete/destroy sensitive information or personal data immediately after accidental access.
  • Publicly disclosing any potential vulnerability without the express written consent of the company.
  • Intentionally or negligently causing a denial-of-service condition for any user beyond the researcher.
  • Exploiting any vulnerability to send bulk unsolicited or unauthorized messages (spam).
  • Conducting research through social engineering or other deceptive means.
  • Conducting research by physically connecting to a network or device within a facility operated by the company.
  • Conducting research against agricultural machinery, GPS systems, or equipment monitoring devices.
  • Performing security research by employees or contingent staff of the company and controlled subsidiaries and entities in which the company either owns a majority interest or manages operations.

7. Reporting Potential Security Vulnerabilities

7.1 If you believe you have discovered a potential security vulnerability in any digital asset owned, operated, or maintained by the company or a circumstance that could reasonably impact the security of the company or our users, we encourage you to disclose this to us.

7.2 You may report potential security vulnerabilities to us via our Contact Us page.

7.3 Upon submission, we will acknowledge receipt of each vulnerability report, conduct a thorough investigation, and then take appropriate action for resolution, if any.

7.4 While no type of vulnerability is explicitly out of scope of this policy, researchers are asked to consider the attack scenario and exploitability associated with any potential security vulnerability submitted.

8. Contact Information

For questions about this policy or to report a vulnerability, please visit our Contact Us page.