Security and trust

Farm financial data is commercially sensitive. We treat it that way.

A farm business is being asked to hand over its cash position and its exposure. That deserves a plain account of what happens to it.

Your data stays yours

You own every figure you enter and everything AgriRisk derives from it. You can export your risk register, audit trail, projections and score history at any point, and request deletion at any point. We do not sell farm data, and we do not share identifiable farm data with third parties.

UK data residency

Farm data is stored and processed within the UK. Sub-processors are documented, and any change to that list is notified in advance.

Encryption in transit and at rest

All traffic runs over TLS. Data at rest is encrypted at the storage layer, with credentials and integration tokens held separately from application data.

Access control by design

Row-level security means a farm's records are readable only by that farm's own users, and by an adviser the farm has explicitly linked. There is no shared pool of farm data behind the interface.

UK GDPR posture

We hold a record of processing activities, a documented lawful basis for each category of data, a retention schedule matched to your tier, and a subject access request process. Farm financial data is treated as commercially sensitive throughout.

An audit trail you can rely on

Every accepted, deferred or dismissed action is written to an immutable audit record with the reason attached. That record is exportable, which matters when a lender or an adviser asks how a decision was reached.

Multi-source data resilience

Market, weather and index feeds come from several providers by design, so a single outage or a single commercial change does not silence your monitoring. Where a source is unavailable, the interface says so instead of showing stale figures as current.

Integration permissions

Accounting connections use OAuth 2 and request read-only scopes. AgriRisk does not write to your accounting system, and you can revoke the connection from either side.

Reporting a security concern

If you believe you have found a vulnerability in AgriRisk, contact us at security@agririsk.co.uk with enough detail to reproduce it. We acknowledge reports within two working days and will keep you updated until the issue is closed. Please do not test against other customers' accounts.

AgriRisk Limited is registered in the United Kingdom. Data protection enquiries can be sent to the same address and will be handled under our UK GDPR procedures.