Skip to main content

Security & Trust

How we protect customer information. Plain language, no legalese.

BarnX provides private software development, implementation, operational software, and education services for feed, dairy, and livestock businesses — including Cowdemy, Hoof Cowdemy, Feed Cowdemy, and private customer implementations. Protecting customer information is part of how we design, operate, and maintain our services.

This page provides a general summary of our security practices. It does not create a guarantee or replace the terms of an applicable customer agreement. Specific security, hosting, availability, or data residency commitments will be documented in writing where applicable.

Encryption

Data encrypted in transit and at rest.

Access control

Role-based permissions help limit sensitive data to authorized users.

Backups

Automated backups with recovery procedures.

Incident response

Documented process for detecting and responding to security events.

Data hosting

BarnX uses established third-party cloud infrastructure and service providers to host and operate its services, including Cowdemy, Hoof Cowdemy, Feed Cowdemy, and private customer workflow environments.

Hosting locations and configurations may vary depending on the product, customer environment, provider, and agreement. Specific hosting location or data residency requirements are documented in the applicable agreement.

Email, authentication, monitoring, analytics, and support providers may process limited information outside Canada.

Encryption

BarnX uses HTTPS to protect information transmitted between supported browsers, applications, and services.

Production data and backups are protected using encryption and security capabilities provided by infrastructure and platform providers, where applicable.

Access control

Access is restricted based on operational responsibilities and legitimate business need. Practices may include role-based controls, least privilege, authenticated administration, production restrictions, access removal, and activity logging.

Customer users access information according to assigned organizations, roles, and permissions.

Account and application security

Measures may include secure authentication, password hashing, session controls, authorization checks, tenant separation, validation, rate limiting, logging, restricted administration, and monitoring.

Customers are responsible for protecting credentials and removing access that is no longer required.

Backups and recovery

BarnX maintains backup and recovery practices for applicable production systems. Frequency, retention, storage, and procedures vary by product, infrastructure, and agreement.

Recovery times depend on the event; specific recovery commitments must be stated in writing.

Software maintenance and vulnerability management

BarnX reviews dependencies, applies security and maintenance updates, reviews code changes, monitors errors, investigates reported vulnerabilities, limits unsupported components, and prioritizes concerns by severity and operational risk.

No software system can be guaranteed free from vulnerabilities or security risks.

Monitoring and logging

BarnX may use system logs, application logs, error reporting, and monitoring tools to maintain reliability, investigate incidents, diagnose problems, and detect suspicious activity.

Log type and retention vary by service, environment, legal requirements, and operational needs.

Incident response

BarnX maintains a process for assessing and responding to suspected privacy and security incidents, including validation, containment, investigation, correction, restoration, preservation of records, and notifications where required.

Where customer action is necessary, BarnX aims to provide clear, practical information and recommended next steps.

Hosting locations depend on the BarnX product, infrastructure configuration, and applicable customer agreement. Contact BarnX about a specific environment.
Available export methods depend on the product and customer agreement. Contact BarnX support to discuss options.
Authorized customer users access information by role and permission. Authorized BarnX personnel may access it when reasonably necessary for support, maintenance, security, incident investigation, legal compliance, or service administration.
BarnX reviews security notices, dependencies, and reported issues. Updates are prioritized by severity, exposure, compatibility, testing requirements, and operational risk.
BarnX investigates, takes reasonable steps to contain and correct the issue, and provides notifications where required by law or contract.
Send reports to security@barnx.ca. Include a description, the affected page or service, reproduction steps, and contact information. Do not access, alter, download, disclose, or disrupt data or services.