Version: 1.0
Latest update: August 19, 2026
Vulnerability Disclosure Policy
1. Introduction
At ZELP, the security of our products and systems is a priority. Our devices are used on working farms and in research centres, and process sensitive customer data. Protecting these products and the information they handle is therefore an essential part of what we do.
Despite best efforts, vulnerabilities can never be completely eliminated. If they are identified and exploited, they may put at risk the confidentiality, integrity or availability of ZELP’s products and the information they process.
This policy describes which products and systems are in scope, what types of testing are authorised, how to send us a vulnerability report, and what you can expect from us in return.
We welcome reports from security researchers, customers, farm operators and any other party. This policy is published openly and may be used by anyone without prior registration, invitation or request.
2. Authorisation
If you are acting in good faith to identify and report vulnerabilities in ZELP products and systems, and you comply with this policy, we will work with you to understand and resolve the issue quickly.
ZELP will not initiate or support legal action in relation to your activities in identifying vulnerabilities, as long as you follow the guidelines in this policy. See Section 9 for further details on the legal protections and limitations that apply.
3. Scope
This policy applies to:
- ZELP Sense: the device, its embedded firmware, its wireless interfaces, and the mobile or web applications used to provision and manage it
- ZELP Insight: the data platform at insight.zelp.co, including its web application and APIs
- The ZELP website at zelp.co
- The cloud infrastructure supporting the above
Any product or system not expressly listed above is excluded from scope and is not authorised for testing. This includes systems operated by our customers, farms, distributors or other third parties, even where they process ZELP data.
Vulnerabilities in third-party or vendor components that ZELP does not control should be reported directly to the vendor under their own disclosure policy. However, if the issue relates to how ZELP has integrated, configured, or deployed that component, please report it to us.
The following are out-of-scope even on in-scope systems:
- Physical attacks on ZELP premises, staff, customer sites or livestock
- Social engineering of ZELP staff, customers or suppliers
- Denial-of-service or volumetric testing of any kind
- Automated scanner output submitted without a demonstrated, exploitable impact
- Missing security headers, weak TLS ciphers, or similar configuration observations with no demonstrated impact
- Any vulnerability requiring physical access to a device fitted to an animal
If you are unsure whether something is in scope, ask us before testing.
4. Guidelines for testing
While carrying out your activities, it is essential that you:
- Do not take advantage of the vulnerability you have discovered, for example by downloading more data than is necessary to demonstrate it, or by deleting or modifying other people's data
- Use only harmless proof-of-concept activity to confirm that a vulnerability is present
- Test only against your own accounts, your own devices, or systems you have our explicit permission to test
- Stop testing immediately if you encounter sensitive information: personal data, health or veterinary records, financial data, proprietary information or trade secrets. Notify us at once, and do not disclose or retain any data you have obtained
- Report your findings to us as soon as possible after discovery
- Do not reveal any data obtained during your research to the public or to any other party
- Do not reveal the vulnerability to the public or to any other party until we confirm it has been resolved.
You must not:
- Take any action that could affect animal welfare, animal health monitoring, or the safe operation of livestock equipment. Our devices are worn by living animals; the safety of those animals takes precedence over any security research
- Interfere with a device that is fitted to an animal
- Place malware of any kind on any system
- Compromise a system to gain full or partial control of it
- Copy, modify or delete data on a system, or otherwise make changes to it
- Repeatedly access a system, or share access with the public or any other party
- Use access obtained to attempt to reach other systems
- Change the access rights of other users
- Use brute-force techniques against any system
- Use automated vulnerability scanning tools, crawlers or other intrusive automated tooling against any ZELP system
- Use denial-of-service techniques, social engineering (phishing, vishing, spam and similar), or attacks on physical security
5. Reporting a vulnerability
Email security@zelp.co.
We only need you to provide an email address so that we can contact you about your report. We do not require your name, employer, address, telephone number or any other personal information, and we will not ask for it.
In your report, please:
- Describe the vulnerability and its likely impact
- Identify the affected product or system, and the version if possible
- Give us enough information to reproduce the problem. Usually the URL, IP address, device ID or MAC address, plus a description will be enough, though complex vulnerabilities may need technical detail or proof-of-concept code
- Include any supporting screenshots or logs that would help us investigate
- Tell us the date, time and source IP address of your testing, if applicable
Please write to us in English if you can.
Please do not include personal data belonging to third parties in your report. If your testing has inadvertently exposed personal data, tell us that it happened, but do not send us the data itself and do not retain a copy.
6. What you can expect from us
| Stage | Our commitment |
|---|---|
| Acknowledgement of receipt | Within 5 business days of your report reaching us |
| Initial assessment (whether we can reproduce the issue and our severity rating) | Within 20 business days of your report reaching us |
| Ongoing status updates | At least once every 30 business days while the report remains open |
| Notification of resolution or closure | Within 10 business days of the report being closed |
All timescales run from the date your report reaches us, not from the date we acknowledge it. If a milestone is going to be missed, we will tell you before it falls due and explain why.
We will also:
- Handle your report in strict confidence, sharing it internally only with those who need it to resolve the issue
- Keep you informed of our progress, including if we decide not to take action and why
- Process any personal data you provide in accordance with applicable data protection law, and not pass your personal details to third parties without your permission (see Section 10)
The time required to resolve a vulnerability depends on its severity, its complexity, and the products or systems affected. Some fixes require a firmware release to devices already deployed; where this is the case, we will tell you the expected release timetable.
7. Coordinated disclosure
We support coordinated disclosure. However, please do not disclose a reported vulnerability to the public or other parties until we confirm the report has been closed.
If you wish to share a reported vulnerability publicly, we ask that you give us a reasonable opportunity to review the write-up before publication so we can check for factual accuracy and confirm that it does not include information that could put our users, systems or data at risk.
Where a vulnerability affects the security of our users, we will take responsibility for notifying affected customers as appropriate.
8. Rewards and recognition
ZELP does not operate a bug bounty programme and we do not offer financial rewards for vulnerability reports.
We treat all reports confidentially and we do not publish the names of reporters.
9. Legal position
ZELP will not initiate or support legal action against anyone who reports a vulnerability in good faith and in accordance with this policy. We consider security research conducted in compliance with this policy to be authorised, and we will not report such activity to law enforcement.
If a third party brings legal action against you in respect of research carried out in compliance with this policy, we will make it known that your activity was authorised by us.
This policy does not authorise activity that breaks the law, and it cannot bind third parties. It gives no permission to act on systems operated by our customers or suppliers. If you are unsure whether a particular action is permitted, ask us first at security@zelp.co.
10. How we handle your personal data
If you report a vulnerability, we process the email address you give us, and any personal data contained in your report, in order to investigate the issue and communicate with you about it. ZELP is the data controller for this processing, and our lawful basis is our legitimate interest in maintaining the security of our products and services.
We retain vulnerability reports and related correspondence for 5 years from closure, for audit and product-security purposes. We do not use your contact details for marketing, and we will not pass them to third parties without your permission, except where we are legally required to. Our full privacy notice is available at zelp.co/privacy.
11. Changes to this policy
We may update this policy from time to time. The current version and its date are shown at the top of this policy.