Product Security & Vulnerability Disclosure Policy

At DigiDevice, we take the security of our systems, applications, and products seriously. If you have discovered a security vulnerability, we appreciate your help in disclosing it to us in a responsible manner.

Scope

This policy applies to:

  • Our core web applications and cloud infrastructure (*.digidevice.com)
  • Our telemetry platforms and web applications (*.agrilog.cloud)
  • Mobile and PWA applications (including Silo Monitor and connected telemetry systems)
  • IoT central units and proprietary hardware firmware

Reporting Guidelines

If you identify a potential vulnerability, please:

  1. Share the details with us via email at security@digidevice.com.
  2. Encrypt your report using our PGP Public Key (linked below) to protect sensitive data.
  3. Provide a detailed description of the vulnerability, including steps to reproduce, exact URLs, and a Proof of Concept (PoC) if available.
  4. Give us a reasonable amount of time to investigate and remediate the issue before public disclosure (Coordinated Vulnerability Disclosure).

Please DO NOT:

  • Perform Denial of Service (DoS/DDoS) attacks.
  • Exfiltrate, modify, or destroy customer or corporate data.
  • Use automated scanners that generate high traffic volume.

Our Commitment

If you follow these guidelines, we commit to:

  • Acknowledge receipt of your report within 3 business days.
  • Provide an estimated timeline for triage and remediation.
  • Not initiate legal action against you, provided you act in good faith and adhere to this policy.

PGP Public Key

You can download our PGP Public Key here to encrypt your communications.