Security Whitepaper

How RanchPad protects your farm data — architecture, practices, and compliance.

Version 1.0 — January 2026

1. Executive Summary

RanchPad is committed to protecting the security, integrity, and availability of customer data. This whitepaper describes the security architecture, processes, and controls implemented across the platform. Our approach follows defence-in-depth principles with multiple layers of protection.

2. Infrastructure Security

Cloud Hosting

Hosted on enterprise-grade cloud infrastructure with ISO 27001, SOC 2 Type II, and PCI DSS certifications. Regional data centres in Oceania, Europe, and North America.

Network Security

Web Application Firewall (WAF), DDoS protection, and private VPC networking. All inter-service communication encrypted via mutual TLS.

Redundancy

Multi-availability-zone deployment with automated failover. Database replication with point-in-time recovery up to 35 days.

Backups

Automated daily backups with geographic redundancy. Backup encryption at rest. Regular restoration testing to verify integrity.

3. Application Security

Authentication
Authorisation
Data Protection

4. Secure Development Lifecycle

PhaseSecurity Activity
DesignThreat modelling, security architecture review
DevelopmentSecure coding standards, peer code review, static analysis (SAST)
TestingAutomated security testing, dependency vulnerability scanning
DeploymentContainer image scanning, infrastructure-as-code review
OperationsRuntime monitoring, intrusion detection, log analysis

5. Incident Response

RanchPad maintains a formal incident response plan with defined roles, escalation procedures, and communication templates:

  1. Detection — Automated monitoring and alerting for anomalous activity
  2. Triage — Severity classification (Critical, High, Medium, Low)
  3. Containment — Immediate threat containment with minimal service disruption
  4. Investigation — Root cause analysis and evidence preservation
  5. Notification — Customer notification within 72 hours of confirmed data breach
  6. Recovery — Service restoration and security hardening
  7. Post-mortem — Lessons learned and preventive measures

6. Compliance & Certifications

7. Audit Logging

RanchPad maintains comprehensive audit logs including:

Audit logs are retained for a minimum of 12 months and are tamper-protected.

8. Responsible Disclosure

We welcome responsible disclosure of security vulnerabilities. If you discover a security issue, please report it to security@ranchpad.co.nz. We commit to acknowledging reports within 48 hours and providing regular updates on remediation progress.