We actively support the following versions with security updates:
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
If you discover a security vulnerability in AgriCredit, please help us by reporting it responsibly.
Please do NOT report security vulnerabilities through public GitHub issues.
Instead, please report security vulnerabilities by emailing security@agricredit.com.
When reporting a vulnerability, please include:
- A clear description of the vulnerability
- Steps to reproduce the issue
- Potential impact and severity
- Any suggested fixes or mitigations
- Your contact information for follow-up
- Acknowledgment: We will acknowledge receipt of your report within 48 hours
- Investigation: Our security team will investigate and validate the vulnerability
- Updates: We will provide regular updates on our progress (at least weekly)
- Resolution: Once resolved, we will notify you and coordinate disclosure timing
- Credit: With your permission, we will credit you in our security advisory
- We follow a 90-day disclosure timeline from the initial report
- We will coordinate disclosure with you to ensure responsible disclosure
- We will publish security advisories on our website and GitHub Security Advisories
- Always connect to the official AgriCredit website
- Use strong, unique passwords
- Enable two-factor authentication when available
- Keep your wallet software updated
- Never share your private keys or seed phrases
- Follow secure coding practices
- Use parameterized queries to prevent SQL injection
- Implement proper input validation
- Use HTTPS for all communications
- Regularly update dependencies
- Conduct security audits before major releases
AgriCredit implements several security measures:
- Blockchain Security: All transactions are recorded on immutable blockchain ledgers
- Smart Contract Audits: Regular third-party security audits of smart contracts
- Encryption: End-to-end encryption for sensitive data
- Access Controls: Role-based access control for different user types
- Monitoring: 24/7 monitoring for suspicious activities
- Backup Systems: Regular backups with secure storage
We run a bug bounty program to encourage security research. Eligible vulnerabilities include:
- Remote code execution
- SQL injection
- Cross-site scripting (XSS)
- Cross-site request forgery (CSRF)
- Authentication bypass
- Privilege escalation
- Smart contract vulnerabilities
Rewards are determined based on severity:
- Critical: Up to $10,000
- High: Up to $5,000
- Medium: Up to $2,000
- Low: Up to $500
For security-related questions or concerns, contact us at security@agricredit.com.
Thank you for helping keep AgriCredit secure!