Agribantu / Legal / Security & Trust Statement

Legal

Agribantu Security & Trust Statement

Agribantu's public security principles, the responsibilities shared between Agribantu and its customers, and how to report a suspected vulnerability.

Version 1.0 Effective date: 17 July 2026

1. Purpose

Agribantu provides software for people, livestock, financial, movement, organisational and regulatory operations.

Protecting the confidentiality, integrity and availability of information is therefore fundamental to the Agribantu platform.

This Security & Trust Statement describes Agribantu’s public security principles and the responsibilities shared between Agribantu, its customers and authorised users.

It does not disclose confidential security architecture, credentials, defensive configurations or information that could assist an attacker.

2. Scope

This statement applies to:

  • agribantu.co.za;
  • agribantu.com;
  • app.agribantu.com;
  • api.agribantu.com;
  • Agribantu mobile applications;
  • supporting infrastructure;
  • approved integrations; and
  • personnel and service providers involved in operating the Services.

3. Security objectives

Agribantu’s security approach is intended to support:

Confidentiality

Information should be accessible only to authorised persons and systems.

Integrity

Information should remain accurate, complete and protected against unauthorised alteration.

Availability

Services and information should remain available in accordance with applicable operational commitments.

Accountability

Material access and actions should be attributable and capable of appropriate review.

Resilience

Agribantu should be able to detect, respond to and recover from security events.

4. Shared responsibility

Security is shared between Agribantu and each customer.

Agribantu is responsible for

  • securing the platform components under its control;
  • implementing server-side access controls;
  • maintaining platform authentication and authorisation mechanisms;
  • protecting production credentials and infrastructure;
  • applying appropriate updates and security fixes;
  • monitoring relevant operational and security events;
  • maintaining incident-response procedures; and
  • managing service providers used by Agribantu.

Customers are responsible for

  • deciding who receives access;
  • assigning appropriate roles and scopes;
  • removing access promptly when no longer required;
  • protecting user credentials;
  • securing customer-controlled devices and networks;
  • configuring integrations safely;
  • ensuring that API credentials are not exposed;
  • reviewing audit and exception information;
  • providing lawful privacy and monitoring notices;
  • exporting or retaining records required by the customer; and
  • notifying Agribantu promptly of suspected compromise.

5. Tenant and organisation separation

Agribantu is designed as a multi-organisation platform.

Customer information is logically separated through tenant, organisation, role, scope and resource-level controls.

Authorisation is enforced by the server. Hiding a page or button in the user interface is not treated as sufficient security.

Sensitive operations should validate:

  • the authenticated user;
  • the active tenant;
  • the relevant organisation;
  • the user’s current role;
  • assigned scopes or capabilities;
  • jurisdiction or administrative boundaries where applicable; and
  • ownership or management relationships where required.

6. Identity and access management

Agribantu applies role- and scope-based access controls to limit what an authorised user may view or perform.

Access decisions may take account of:

  • platform role;
  • organisation role;
  • direct-report relationship;
  • assigned team;
  • institution;
  • jurisdiction;
  • office;
  • authority position;
  • enabled module; and
  • customer subscription.

Customers should apply the principle of least privilege and provide each user only the access needed for their duties.

7. Authentication and sessions

Agribantu uses authenticated sessions for protected services.

Security measures may include:

  • protected authentication cookies or tokens;
  • session expiry;
  • server-side validation;
  • password controls;
  • account or access revocation;
  • device-session management;
  • protection against unauthorised cross-site requests;
  • authentication-event logging; and
  • additional verification for sensitive operations where implemented.

Users must not share passwords, session credentials, invitation codes or API secrets.

Agribantu will never ask a user to provide their password through ordinary email or social media.

8. Communications security

Agribantu requires secure encrypted communication for production web and API traffic.

Customers and integrations must use supported HTTPS endpoints and must validate certificates correctly.

Unencrypted protocols should not be used for credentials, personal information or production API traffic.

9. Application and API security

Agribantu’s application-security approach includes controls intended to address:

  • authentication and authorisation failures;
  • insecure direct-object references;
  • injection attacks;
  • cross-site scripting;
  • cross-site request forgery;
  • unsafe file handling;
  • excessive data exposure;
  • insecure error responses;
  • API abuse;
  • tenant-boundary failures;
  • dependency vulnerabilities; and
  • accidental disclosure of credentials or tokens.

API access must use authorised credentials and documented endpoints.

Agribantu may apply:

  • request validation;
  • permission checks;
  • rate limiting;
  • credential rotation;
  • idempotency controls;
  • replay protections;
  • audit logging;
  • version controls; and
  • suspension of abusive or compromised credentials.

API keys and service credentials must never be placed in public source repositories or client-side code where unauthorised persons can retrieve them.

10. Secure software development

Agribantu’s development process is intended to include:

  • source-control protection;
  • peer or automated review;
  • automated testing;
  • type and build validation;
  • dependency review;
  • security-focused tests for sensitive workflows;
  • separation of development and production configuration;
  • controlled deployment;
  • rollback capability; and
  • post-deployment verification.

Security-sensitive changes should receive review proportionate to the risk presented.

Production data should not be copied into development or demonstration environments unless properly authorised and protected.

11. Infrastructure and operational security

Agribantu uses hosting, database, communication and infrastructure providers to operate the Services.

Operational measures may include:

  • restricted administrative access;
  • network and service configuration;
  • environment separation;
  • secrets management;
  • security updates;
  • malware and abuse prevention;
  • infrastructure logging;
  • service-health monitoring;
  • resource and capacity monitoring; and
  • controlled administrative tools.

Specific infrastructure details may be withheld where disclosure would create an unnecessary security risk.

12. Encryption and stored information

Agribantu uses encryption in transit for production web and API communications.

The use of encryption at rest depends on the relevant hosting, database, backup and device environment.

Before publishing a stronger claim such as “all customer data is encrypted at rest,” Agribantu must verify that the claim applies to active databases, file storage, logs, backups, replicas, exports, mobile-device storage, and all relevant service providers. That verification has not yet been completed and published — treat encryption-at-rest coverage as unconfirmed until this section is updated.

Passwords must not be stored in readable form.

Production secrets should be stored separately from public application source code and should be accessible only to authorised systems or personnel.

13. Logging and auditability

Agribantu records selected operational and security events to support:

  • accountability;
  • troubleshooting;
  • misuse detection;
  • incident investigation;
  • regulatory workflows; and
  • customer review.

Depending on the feature, records may include:

  • authentication events;
  • access changes;
  • administrative actions;
  • regulatory submissions;
  • acknowledgements;
  • location-access events;
  • configuration changes;
  • notification activity;
  • security errors; and
  • API operations.

Logs are themselves protected information and access to them must be restricted.

Audit logs reduce risk but do not guarantee that every action or event will always be recorded.

14. Location and mobile security

Agribantu mobile and location functionality may involve:

  • background location;
  • GPS observations;
  • notification credentials;
  • device identifiers;
  • offline storage;
  • camera or document capture;
  • Bluetooth or connected devices; and
  • communication with authorised tracking systems.

Agribantu aims to:

  • request only permissions required for enabled functionality;
  • communicate why a permission is needed;
  • apply customer-defined access rules;
  • prevent ordinary users from accessing raw service credentials;
  • stop or revoke authorised tracking sessions where the workflow requires it; and
  • avoid exposing sensitive notification or device tokens in ordinary diagnostics.

Customers must secure enrolled devices, use supported operating-system versions and promptly revoke access for lost or reassigned devices.

15. Data minimisation

Agribantu seeks to process only information that is reasonably required for the relevant service.

Customers should avoid uploading unnecessary:

  • identity documents;
  • medical records;
  • financial credentials;
  • criminal or disciplinary information;
  • biometric information;
  • information about children; or
  • other highly sensitive material.

Where a less intrusive field or workflow can achieve the same purpose, the less intrusive option should be preferred.

16. Service providers and subprocessors

Agribantu assesses service providers according to the nature of the service and the information involved.

Relevant provider agreements should address:

  • confidentiality;
  • appropriate security safeguards;
  • authorised processing;
  • incident notification;
  • deletion or return of information;
  • cross-border processing; and
  • assistance with legal compliance.

A subprocessor list should be maintained separately and made available to enterprise customers where appropriate.

17. Backups and continuity

Agribantu’s continuity approach should address:

  • backup frequency;
  • backup protection;
  • restoration procedures;
  • recovery priorities;
  • infrastructure failure;
  • database recovery;
  • service-provider interruption; and
  • communication during material outages.

Public recovery-point or recovery-time commitments apply only where stated in an applicable subscription plan or service-level agreement.

Backups are intended for disaster recovery and are not a substitute for a customer’s own legally required export or archival process.

Not yet published. Specific figures for backup frequency, retention period, geographic backup location, encryption-at-rest status, restoration test frequency, target recovery point and target recovery time have not yet been verified and documented. Do not rely on any particular figure for these until this section is updated with confirmed values.

18. Vulnerability and patch management

Agribantu reviews security vulnerabilities according to their likely impact and exploitability.

Remediation priority may consider:

  • exposure to the public internet;
  • access to personal or customer information;
  • possibility of privilege escalation;
  • tenant-boundary impact;
  • exploit availability;
  • affected service criticality; and
  • available mitigations.

Agribantu may temporarily disable a feature or integration where necessary to address an urgent security risk.

19. Security incident response

Agribantu’s incident-response process is intended to cover:

  • identification and reporting;
  • initial triage;
  • containment;
  • preservation of relevant evidence;
  • investigation;
  • assessment of affected information and persons;
  • eradication and remediation;
  • recovery;
  • customer and regulatory notification;
  • post-incident review; and
  • corrective action.

Where Agribantu processes information as an operator, it will notify the responsible customer as required.

Where Agribantu is the responsible party, it will make notifications required under applicable law.

POPIA places security-safeguard obligations on responsible parties and requires operators to notify responsible parties of compromises. Current Regulator guidance confirms that the responsible party retains the formal reporting responsibility.

20. Cybercrime and unlawful access

Unauthorised access, interception, interference, fraud and harmful disclosure may constitute offences under applicable law.

The South African Cybercrimes Act creates offences relating to unlawful access and other cybercrime conduct.

Nothing in this Security Statement authorises a person to:

  • access another person’s account;
  • bypass authentication;
  • access customer information;
  • scan production systems aggressively;
  • disrupt availability;
  • use social engineering;
  • exfiltrate information;
  • install malware;
  • perform denial-of-service testing; or
  • test third-party infrastructure.

21. Reporting a vulnerability

Security researchers and users may report suspected vulnerabilities to: security@agribantu.co.za.

A report should include:

  • the affected service or URL;
  • a clear description of the issue;
  • steps to reproduce it;
  • relevant screenshots or request details;
  • the potential impact;
  • whether any information was accessed;
  • the reporter’s contact information; and
  • any suggested remediation.

Do not include passwords, private keys or unnecessary personal information in an ordinary email.

Agribantu will acknowledge credible reports and will assess them according to severity.

Public disclosure should not occur until Agribantu has had a reasonable opportunity to investigate and remediate the issue.

Active penetration testing requires Agribantu’s prior written authorisation.

22. Customer security responsibilities

Customers should:

  • enforce strong, unique passwords;
  • enable additional authentication controls when available;
  • regularly review users and permissions;
  • promptly disable departed users;
  • protect administrator accounts;
  • secure API and integration credentials;
  • use supported browsers and operating systems;
  • install security updates;
  • protect devices with screen locks and encryption;
  • avoid shared administrator accounts;
  • review audit and exception information;
  • report suspicious activity promptly;
  • maintain suitable internal policies; and
  • train users to recognise phishing and impersonation attempts.

23. Security assurances and certifications

Agribantu will not claim a certification, audit or compliance status that it has not obtained.

Unless expressly stated together with the applicable certificate, report, date and scope, Agribantu does not represent that it is certified under:

  • ISO/IEC 27001;
  • SOC 1 or SOC 2;
  • PCI DSS;
  • CSA STAR;
  • Cyber Essentials; or
  • another external assurance framework.

Using a cloud provider that holds a certification does not automatically make Agribantu itself certified.

Customer-specific security questionnaires may be completed subject to confidentiality and commercial arrangements.

24. No absolute guarantee

Agribantu uses reasonable measures intended to reduce security risk, but no technology platform can guarantee that every threat, error or compromise will be prevented.

This statement does not create an absolute warranty of uninterrupted or vulnerability-free operation.

Contractual security, uptime, recovery and liability commitments are governed by the applicable customer agreement and service-level agreement.

25. Changes to this statement

Agribantu may update this statement as its services, infrastructure, controls, suppliers, risks, or legal obligations change.

The current version and effective date will be displayed at the top.

26. Security contact

Security reportssecurity@agribantu.co.za
Privacy enquiriesprivacy@agribantu.co.za
Customer supporthello@agribantu.co.za

For urgent suspected account compromise, users should contact Agribantu and their organisation administrator immediately.

Found a vulnerability? Report it responsibly to security@agribantu.co.za — see Section 21 before you report.