1. Scope. This policy covers vulnerabilities in AGRON-operated Properties and AGRON-published software. Third-party services are excluded.
2. Safe Harbor. AGRON will not pursue legal action against researchers who (a) act in good faith; (b) avoid privacy violations, destruction of data and degradation of service; (c) provide AGRON a reasonable opportunity to remediate before public disclosure; and (d) comply with this policy.
3. Out of Scope. Testing must not include (a) social engineering of AGRON personnel; (b) denial-of-service testing; (c) physical attacks; (d) automated scanners that generate excessive traffic; or (e) testing that compromises data of other users.
4. Submission. Submit reports to security@agron1.com, encrypted with the PGP key published on the Trust page. Include reproduction steps, impact analysis and any proof-of-concept code.
5. Timeline. Acknowledgement within three (3) business days. Triage update within ten (10) business days. Coordinated disclosure window is ninety (90) days from triage, extendable by mutual agreement.
6. Recognition. With your permission, AGRON publishes a researcher acknowledgement page.
