Security & Trust

Last Updated: July 2026

We take security seriously. This page describes the controls we have in place for Agriexchange.com and how you can responsibly report a vulnerability.

1. Overview

This page is maintained by AgriEx to answer common security and privacy questions about Agriexchange.com. It describes the controls we currently have enabled and how you can report a vulnerability. It is not a certification or a substitute for an independent audit.

2. Platform & Hosting

AgriEx is built on a modern managed cloud stack:

  • Application hosted on an edge network with automated deploys.
  • Managed Postgres database with automatic backups.
  • Payments processed by Stripe — card data never touches our servers.
  • Traffic served over HTTPS with modern TLS.

This is a description of enabled platform capabilities, not an independent certification of the underlying providers.

3. Authentication & Access Control

  • Passwords are hashed at rest by our authentication provider — we never see them in plain text.
  • Sign-in is available with email + password and Google sign-in.
  • Server-side authorisation is enforced by row-level security in the database, so users only see their own private data.
  • Admin actions are logged and restricted to specific user roles.
  • You can sign out from any device at any time from your dashboard.

4. Data Handling

Details on what we collect, why, and how long we keep it are in our Privacy Policy. In summary:

  • We collect only the data needed to run the marketplace, verify sellers, process payments, and communicate with you.
  • Verification documents are stored in a private storage bucket and are only accessible to the uploader and reviewing admins.
  • We do not sell your personal data.

5. Payments

All subscription and advertising payments are processed by Stripe, a PCI-DSS Level 1 certified payment processor. Card numbers, CVCs and full billing details are entered on Stripe-hosted fields and are never stored on AgriEx servers.

6. Your Role — Shared Responsibility

Some parts of keeping your account safe are up to you:

  • Use a strong, unique password and don't reuse it elsewhere.
  • Keep your email account secure — it can be used to reset your AgriEx password.
  • Never share verification codes or session links.
  • Report suspicious messages, listings or accounts using the in-app "Report" action.

7. Reporting a Vulnerability

If you believe you've found a security issue in AgriEx, please disclose it responsibly. Email support@agriexchange.com with the subject line "Security" and include:

  • A clear description of the issue and impact.
  • Steps to reproduce (URLs, sample requests, screenshots).
  • Any account or IP you tested from, so we can filter logs.
  • Whether you'd like to be credited if we publish a fix note.

We ask that you:

  • Give us reasonable time to investigate and remediate before public disclosure.
  • Do not access, modify or delete other users' data.
  • Do not run automated scans that degrade service for other users.
  • Do not perform social-engineering or physical attacks against staff or infrastructure.

Good-faith research conducted under these rules will not be treated as a breach of our Terms of Service or Acceptable Use Policy.

8. Contact

For any security or privacy-related enquiries, email support@agriexchange.com with the subject "Security", or reach us via the Contact page.