1. Posture. Security is treated as a substrate concern, not a layer. Identity, policy and audit are first-class controls across every component.
2. Standards. AGRON aligns with NIST SP 800-53 and SP 800-171 control families, ISO/IEC 27001 management practices, and SOC 2 Trust Services Criteria. Specific certifications are listed on the Trust page when available.
3. Engineering Controls. Production systems use principle of least privilege, mandatory code review, automated dependency scanning, secret scanning, signed builds, immutable infrastructure and continuous vulnerability management.
4. Data Protection. Data is encrypted in transit using modern TLS and at rest using AES-256 or equivalent. Key management uses HSM-backed services with documented rotation.
5. Incident Response. AGRON maintains a documented incident response plan with named roles, communication paths, and post-incident review. Customer-affecting incidents are communicated under contract.
6. Business Continuity. AGRON maintains backup, restoration and disaster-recovery procedures, with recovery objectives documented and tested.
7. External Engagement. Reports are received through Responsible Disclosure. AGRON does not threaten or pursue legal action against good-faith security researchers acting within our policy.
8. Contact. security@agron1.com (PGP key on the Trust page).
