JustFarm
AI-powered SaaS platform helping UK farmers and agents navigate Environmental Land Management scheme (ELMs) applications. Supports transition from Basic Payment Scheme (BPS) to ELMs including Countryside Stewardship (CS) and Sustainable Farming Incentive (SFI). Simplifies DEFRA compliance, automates application processes, and maximises subsidy eligibility for farming businesses across England.
Features
- AI-powered application support for DEFRA Environmental Land Management schemes
- AI-assisted eligibility assessment for SFI and Countryside Stewardship
- Multi-farm dashboard for agents managing multiple client applications
- Real-time updates to latest scheme rules so farmers stay compliant
- Secure cloud storage for action evidence. Automated inspection reports.
- Deadline reminders for annual declarations and application windows
- AI-powered mapping of ELMs agreements for easy management.
- Secure data-capture to organise evidence and ensure compliance.
- Collaboration so farmers/advisors can track ELMs objectives
- ELMs guidance and support - delivered in plain english!
Benefits
- Maximize farm income through accurate eligibility assessment
- Reduce application rejection rates with complete accurate submissions
- Save days of admin time with automated workflows
- Manage multiple farm applications from one centralized dashboard
- Never miss DEFRA deadlines with automated reminders
- Stay compliant with latest scheme requirements automatically
- Simplify transition from Basic Payment to ELM schemes
- Track compliance progress to ensure alignment with ELMs goals
- Access plain English guidance on complex scheme requirements
- Prepare confidently for inspections with organised evidence
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 8 8 4 8 4 7 4 8 9 9 1 3 8 0
Contact
JustFarm
James Stretton
Telephone: 07776130304
Email: contact@justfarm.app
About your service
- Service categories
-
Applications
Content workflow and management
- Capture
- Document
Content services
- Enterprise Content Management Applications
- Content Sharing and Collaboration Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Requires internet connection and modern web browser (Chrome, Firefox, Safari, Edge - current and previous version).
- System requirements
- Internet connection and modern web browser.
User support
- Email or online ticketing support
- Yes
- Support response times
- Support hours are 9am-5pm, Monday-Friday. Emails are responded to within 48 hours.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
STANDARD SUPPORT (included in subscription):
- Email and online ticketing support: contact@justfarm.app
- Response within 48 hours for standard queries
- Video call support available by appointment
- Access to online knowledge base and video tutorials
- Support hours: Monday-Friday 9am-5pm GMT
ENHANCED SUPPORT (available for enterprise clients):
- Dedicated account manager
- Priority email support
- Quarterly review calls
- Custom training sessions for team onboarding
All customers receive software updates, including compliance updates at no additional cost. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
GETTING STARTED SUPPORT (included for all customers):
Online Resources:
- Video tutorial library covering all key features
- Step-by-step user guides
- Searchable knowledge base with FAQs
- Sample application walkthroughs
- Regular webinars on latest features and DEFRA updates
Live Onboarding (available on request):
- Initial setup call (30 minutes) to configure farm details
- Guided walkthrough of the application
Enhanced Training (for enterprise clients):
- Custom team training sessions
- Dedicated onboarding support
All training materials use plain English and are designed specifically for the farming sector. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Users can produce 'Inspection Reports' which produce a zip file containing all of the documentation and evidence uploaded into the platform. Once extracted, they can then delete their account (self-service).
- End-of-contract process
-
END-OF-CONTRACT DATA EXTRACTION (included at no additional cost):
Data Export:
- Full data export provided in standard formats
- Includes all farm records, uploaded evidence, and documentation
- Export can be produced by the user (without requiring additional support)
Notice Period:
- Rolling monthly subscription - cancel anytime with 30 days notice
- Annual subscriptions cancel on next renewal date.
- No exit fees or penalties for contract termination
Data Security After Contract End:
- User can delete their account, including all underlying data (without requiring additional support) - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile 'companion app' allows users to see what their ELMs obligations are while out on-the-farm. They can capture and upload evidence through the app.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
JustFarm has a web-based interface where farmers and agents log in to:
View their farms
Prepare ELM applications
Track deadlines
Store evidence
Access guidance
Collaborate with other users on the farm
Produce reports to support inspections - Accessibility standards
- None or don’t know
- Description of accessibility
- We haven't specifically tested for accessibility but have committed to achieving AA by September 2026.
- Accessibility testing
- Formal accessibility testing with assistive technology users is scheduled as part of our WCAG 2.2 AA compliance roadmap before framework award date. We have conducted initial automated accessibility testing using axe DevTools and manual keyboard navigation testing.
- API
- No
- Customisation available
- Yes
- Description of customisation
- Enterprise clients are able to customise some of the look-and-feel of the platform, for example using their own logo in the platform and on reports.
Scaling
- Independence of resources
-
Infrastructure Design:
- Cloud-native architecture hosted on Azure with auto-scaling capabilities
- Load balancing distributes traffic across multiple servers
Performance Protection:
- Multi-tenant architecture with logical data separation
- Rate limiting prevents individual users from monopolizing resources
- Monitoring alerts trigger automatic capacity increases
- 99.5% uptime SLA commitment
Capacity Management:
- Infrastructure automatically scales based on demand
- Performance monitoring 24/7 with automated alerts
- Regular load testing to ensure system handles concurrent users
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users can export their data in a .zip file. This can include ALL of their data, or a selected sub-set of data. Process is initiated by the user and does not require external support.
- Data export formats
- Other
- Other data export formats
- Data is exported in original format.
- Data import formats
- Other
- Other data import formats
-
- We import land data from the RPA's API
- We ingest pdf ELM agreement documents.
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Availability Commitment:
- 99.5% uptime measured monthly (approximately 3.6 hours maximum downtime per month)
- Excludes scheduled maintenance windows (announced 7 days in advance)
- Excludes force majeure events (e.g., third-party cloud provider outages beyond our control) - Approach to resilience
-
Infrastructure Resilience:
- Hosted on Azure cloud infrastructure
- Load-balanced architecture ensures automatic failover if one server fails
- Auto-scaling responds to traffic spikes or server failures
- No single points of failure in production architecture
Data Protection:
- Automated daily backups with 30-day retention
- Backups stored in geographically separate location from primary data
Monitoring and Response:
- 24/7 automated monitoring of system health and performance
- Automated alerts trigger immediate investigation of anomalies
- Incident response procedures for rapid resolution
Disaster Recovery:
- Recovery Time Objective (RTO): 4 hours maximum for full service restoration
- Recovery Point Objective (RPO): Maximum 24 hours data loss (daily backup window)
- Tested disaster recovery procedures updated quarterly
Physical Datacentre Resilience:
Managed by Azure including redundant power, cooling, network connectivity, and physical security. Full datacentre specifications available on request. - Outage reporting
-
OUTAGE COMMUNICATION:
Proactive Notifications:
- Email alerts to all users when incidents detected
- All-clear notification when service restored
- Post-incident reports published for major outages
Planned Maintenance:
- Minimum 7 days advance notice via email
Support Channels During Outages:
- Support email remains available for incident-specific queries
- Emergency contact information provided for critical deadline-related issues
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
JustFarm's admin interface uses non-standard URL paths, honeypot protection to detect unauthorized access attempts, and strict rate limiting to prevent brute force attacks. Multi-factor authentication (2FA) is mandatory for all administrative users.
Role-based access control (RBAC) implements least privilege principles with granular permissions across organization and farm levels. Quarterly access reviews ensure appropriate privileges.
Support access to customer environments requires explicit approval and is logged for audit purposes. Privileged operations use Azure AD service principals with minimal necessary permissions. Azure Key Vault credentials undergo quarterly rotation. Administrative sessions use secure HttpOnly cookies with automatic invalidation upon password changes. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
-
SECURITY GOVERNANCE APPROACH:
Current State:
- Implementing security best practices aligned with ISO 27001 framework
- Security policies covering access control, data protection, incident response
- Regular security reviews and vulnerability assessments
- Secure development lifecycle practices
Planned Certifications:
- Cyber Essentials certification: Target Q3 2026
- Cyber Essentials Plus: Target Q1 2027
- ISO 27001 certification: Target 2027
Security Practices:
- Annual third-party penetration testing
- Quarterly vulnerability scanning
- Staff security awareness training
- Incident response procedures documented and tested
- Data classification and handling policies
- Access control and least privilege principles - Information security policies and processes
-
INFORMATION SECURITY FRAMEWORK:
Governance Structure:
James Stretton (Founder & CEO) serves as Information Security Officer with direct accountability. Documented Security Policy (v3.0) maintained and reviewed quarterly by Security Owner.
Core Policies Implemented:
Access Control: Firebase authentication with mandatory MFA for admins, optional for users. Organization-based RBAC with least privilege enforcement. Regular access reviews quarterly.
Data Protection: AES-256 encryption at rest, TLS 1.2+ in transit. UK GDPR compliant with documented data retention (user data: 90 days post-contract; business data: 7 years regulatory). Azure Key Vault for secrets management with quarterly rotation.
Vulnerability & Risk Management: Automated scanning via Trivy (CI/CD container scanning) and OWASP ZAP (weekly baseline, monthly full scans). Microsoft Defender suite deployed (Endpoint, Containers, Storage). Critical CVEs patched within 24 hours. High-severity alerts acknowledged within 1 business day.
Incident Response: Documented procedures with severity-based SLAs. Post-incident analysis mandatory for P1/P2 issues. Comprehensive audit logging retained 13 months.
Business Continuity: Daily automated backups, 30-day retention, zone-redundant storage. Point-in-time restore capability (RPO: 5 minutes; RTO: 4 hours).
Certifications: Cyber Essentials target Q3 2026, ISO 27001 alignment in progress. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
CONFIGURATION AND CHANGE MANAGEMENT:
All changes deployed via automated CI/CD pipelines with mandatory security gates. Trivy blocks CRITICAL vulnerabilities pre-deployment; OWASP ZAP validates runtime security (weekly baseline, monthly full scans).
Production changes require code review and approval. Infrastructure-as-Code manages all configurations with version control. Azure Policy Assignments enforce security baselines.
Patch Management: Critical CVEs within 24 hours. AKS auto-patched; application dependencies updated monthly minimum.
Audit Trail: All deployments logged (timestamp, author, changes). Configuration compliance reviewed quarterly. Security Policy v3.0 maintained with quarterly reviews.
Working towards formal certification alignment (CSA CCM/ISO 27001) by 2027. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Automated Scanning:
- Trivy container scanning in CI/CD blocks CRITICAL vulnerabilities pre-deployment
- OWASP ZAP scans: weekly baseline, monthly full active scans on all public endpoints
- Microsoft Defender suite (Endpoint, Containers, Storage) provides runtime monitoring
Remediation SLAs:
- CRITICAL vulnerabilities: 7 days maximum
- Base images refreshed monthly or upon critical CVE advisories
- Application dependencies updated monthly minimum
Monitoring & Response:
- P1 alerts acknowledged and triaged within 1 business day
- Security scan artifacts retained 13 months for audit trail
- Weekly review of Defender for Cloud recommendations
- Quarterly security reporting - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Real-Time Monitoring:
- Microsoft Defender for Cloud monitors all Azure resources with automated alerting
- Defender for Endpoint (EDR) on AKS nodes provides anti-malware and behavioral detection
- Sentry monitors application exceptions and security events
- Network monitoring via Azure Application Gateway and Firewall
Security Alerting:
- High-severity alerts notify Security Admins within 15 minutes
- P1 alerts acknowledged within 1 business day
- Weekly security recommendation reviews
Audit Logging:
- Comprehensive logging of authentication, access attempts, permission changes
- Activity logs retained 13 months (immutable, PII-excluded)
- Monthly reporting tracks alert volumes, vulnerability findings, SLA adherence - Incident management type
- Supplier-defined controls
- Incident management approach
-
JustFarm maintains documented incident procedures with severity-based classification (P1/P2/P3) and defined SLAs. P1 incidents receive acknowledgment within 1 business day with immediate containment. Pre-defined playbooks exist for security breaches, outages, and common events. Automated monitoring via Microsoft Defender and Sentry triggers incident workflows.
Incident reporting includes: initial notification within 15 minutes, hourly progress updates, immediate resolution communication, and root cause analysis within 48 hours for major incidents. All incidents tracked with mandatory post-mortems for P1/P2, ensuring continuous improvement. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Users can create their farm, upload their agreement documents and see their ELMs actions mapped over their farm. Users can then view advice on what they need to do to stay compliant.
- Link to free trial
- https://justfarm.app
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 20%
- Between £250,000 and £500,000
- 20%
- Between £500,001 and £1,000,000
- 20%
- Between £1,000,001 and £2,500,000
- 25%
- Between £2,500,001 and £5,000,000
- 25%
- Over £5,000,001
- 30%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-