Skip to main content

Help us improve the Digital Marketplace - send your feedback

JustFarm

JustFarm

AI-powered SaaS platform helping UK farmers and agents navigate Environmental Land Management scheme (ELMs) applications. Supports transition from Basic Payment Scheme (BPS) to ELMs including Countryside Stewardship (CS) and Sustainable Farming Incentive (SFI). Simplifies DEFRA compliance, automates application processes, and maximises subsidy eligibility for farming businesses across England.

Features

  • AI-powered application support for DEFRA Environmental Land Management schemes
  • AI-assisted eligibility assessment for SFI and Countryside Stewardship
  • Multi-farm dashboard for agents managing multiple client applications
  • Real-time updates to latest scheme rules so farmers stay compliant
  • Secure cloud storage for action evidence. Automated inspection reports.
  • Deadline reminders for annual declarations and application windows
  • AI-powered mapping of ELMs agreements for easy management.
  • Secure data-capture to organise evidence and ensure compliance.
  • Collaboration so farmers/advisors can track ELMs objectives
  • ELMs guidance and support - delivered in plain english!

Benefits

  • Maximize farm income through accurate eligibility assessment
  • Reduce application rejection rates with complete accurate submissions
  • Save days of admin time with automated workflows
  • Manage multiple farm applications from one centralized dashboard
  • Never miss DEFRA deadlines with automated reminders
  • Stay compliant with latest scheme requirements automatically
  • Simplify transition from Basic Payment to ELM schemes
  • Track compliance progress to ensure alignment with ELMs goals
  • Access plain English guidance on complex scheme requirements
  • Prepare confidently for inspections with organised evidence

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at contact@justfarm.app. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 8 8 4 8 4 7 4 8 9 9 1 3 8 0

Contact

JustFarm James Stretton
Telephone: 07776130304
Email: contact@justfarm.app

About your service

Service categories

Applications

Content workflow and management

  • Capture
  • Document

Content services

  • Enterprise Content Management Applications
  • Content Sharing and Collaboration Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Requires internet connection and modern web browser (Chrome, Firefox, Safari, Edge - current and previous version).
System requirements
Internet connection and modern web browser.

User support

Email or online ticketing support
Yes
Support response times
Support hours are 9am-5pm, Monday-Friday. Emails are responded to within 48 hours.
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
STANDARD SUPPORT (included in subscription):
- Email and online ticketing support: contact@justfarm.app
- Response within 48 hours for standard queries
- Video call support available by appointment
- Access to online knowledge base and video tutorials
- Support hours: Monday-Friday 9am-5pm GMT

ENHANCED SUPPORT (available for enterprise clients):
- Dedicated account manager
- Priority email support
- Quarterly review calls
- Custom training sessions for team onboarding

All customers receive software updates, including compliance updates at no additional cost.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
GETTING STARTED SUPPORT (included for all customers):

Online Resources:
- Video tutorial library covering all key features
- Step-by-step user guides
- Searchable knowledge base with FAQs
- Sample application walkthroughs
- Regular webinars on latest features and DEFRA updates

Live Onboarding (available on request):
- Initial setup call (30 minutes) to configure farm details
- Guided walkthrough of the application

Enhanced Training (for enterprise clients):
- Custom team training sessions
- Dedicated onboarding support

All training materials use plain English and are designed specifically for the farming sector.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
Users can produce 'Inspection Reports' which produce a zip file containing all of the documentation and evidence uploaded into the platform. Once extracted, they can then delete their account (self-service).
End-of-contract process
END-OF-CONTRACT DATA EXTRACTION (included at no additional cost):

Data Export:
- Full data export provided in standard formats
- Includes all farm records, uploaded evidence, and documentation
- Export can be produced by the user (without requiring additional support)

Notice Period:
- Rolling monthly subscription - cancel anytime with 30 days notice
- Annual subscriptions cancel on next renewal date.
- No exit fees or penalties for contract termination

Data Security After Contract End:
- User can delete their account, including all underlying data (without requiring additional support)
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile 'companion app' allows users to see what their ELMs obligations are while out on-the-farm. They can capture and upload evidence through the app.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
JustFarm has a web-based interface where farmers and agents log in to:

View their farms
Prepare ELM applications
Track deadlines
Store evidence
Access guidance
Collaborate with other users on the farm
Produce reports to support inspections
Accessibility standards
None or don’t know
Description of accessibility
We haven't specifically tested for accessibility but have committed to achieving AA by September 2026.
Accessibility testing
Formal accessibility testing with assistive technology users is scheduled as part of our WCAG 2.2 AA compliance roadmap before framework award date. We have conducted initial automated accessibility testing using axe DevTools and manual keyboard navigation testing.
API
No
Customisation available
Yes
Description of customisation
Enterprise clients are able to customise some of the look-and-feel of the platform, for example using their own logo in the platform and on reports.

Scaling

Independence of resources
Infrastructure Design:
- Cloud-native architecture hosted on Azure with auto-scaling capabilities
- Load balancing distributes traffic across multiple servers

Performance Protection:
- Multi-tenant architecture with logical data separation
- Rate limiting prevents individual users from monopolizing resources
- Monitoring alerts trigger automatic capacity increases
- 99.5% uptime SLA commitment

Capacity Management:
- Infrastructure automatically scales based on demand
- Performance monitoring 24/7 with automated alerts
- Regular load testing to ensure system handles concurrent users

Analytics

Service usage metrics
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Users can export their data in a .zip file. This can include ALL of their data, or a selected sub-set of data. Process is initiated by the user and does not require external support.
Data export formats
Other
Other data export formats
Data is exported in original format.
Data import formats
Other
Other data import formats
  • We import land data from the RPA's API
  • We ingest pdf ELM agreement documents.

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Availability Commitment:
- 99.5% uptime measured monthly (approximately 3.6 hours maximum downtime per month)
- Excludes scheduled maintenance windows (announced 7 days in advance)
- Excludes force majeure events (e.g., third-party cloud provider outages beyond our control)
Approach to resilience
Infrastructure Resilience:
- Hosted on Azure cloud infrastructure
- Load-balanced architecture ensures automatic failover if one server fails
- Auto-scaling responds to traffic spikes or server failures
- No single points of failure in production architecture

Data Protection:
- Automated daily backups with 30-day retention
- Backups stored in geographically separate location from primary data

Monitoring and Response:
- 24/7 automated monitoring of system health and performance
- Automated alerts trigger immediate investigation of anomalies
- Incident response procedures for rapid resolution

Disaster Recovery:
- Recovery Time Objective (RTO): 4 hours maximum for full service restoration
- Recovery Point Objective (RPO): Maximum 24 hours data loss (daily backup window)
- Tested disaster recovery procedures updated quarterly

Physical Datacentre Resilience:
Managed by Azure including redundant power, cooling, network connectivity, and physical security. Full datacentre specifications available on request.
Outage reporting
OUTAGE COMMUNICATION:

Proactive Notifications:
- Email alerts to all users when incidents detected
- All-clear notification when service restored
- Post-incident reports published for major outages

Planned Maintenance:
- Minimum 7 days advance notice via email

Support Channels During Outages:
- Support email remains available for incident-specific queries
- Emergency contact information provided for critical deadline-related issues

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
JustFarm's admin interface uses non-standard URL paths, honeypot protection to detect unauthorized access attempts, and strict rate limiting to prevent brute force attacks. Multi-factor authentication (2FA) is mandatory for all administrative users.

Role-based access control (RBAC) implements least privilege principles with granular permissions across organization and farm levels. Quarterly access reviews ensure appropriate privileges.

Support access to customer environments requires explicit approval and is logged for audit purposes. Privileged operations use Azure AD service principals with minimal necessary permissions. Azure Key Vault credentials undergo quarterly rotation. Administrative sessions use secure HttpOnly cookies with automatic invalidation upon password changes.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
SECURITY GOVERNANCE APPROACH:

Current State:
- Implementing security best practices aligned with ISO 27001 framework
- Security policies covering access control, data protection, incident response
- Regular security reviews and vulnerability assessments
- Secure development lifecycle practices

Planned Certifications:
- Cyber Essentials certification: Target Q3 2026
- Cyber Essentials Plus: Target Q1 2027
- ISO 27001 certification: Target 2027

Security Practices:
- Annual third-party penetration testing
- Quarterly vulnerability scanning
- Staff security awareness training
- Incident response procedures documented and tested
- Data classification and handling policies
- Access control and least privilege principles
Information security policies and processes
INFORMATION SECURITY FRAMEWORK:

Governance Structure:
James Stretton (Founder & CEO) serves as Information Security Officer with direct accountability. Documented Security Policy (v3.0) maintained and reviewed quarterly by Security Owner.

Core Policies Implemented:

Access Control: Firebase authentication with mandatory MFA for admins, optional for users. Organization-based RBAC with least privilege enforcement. Regular access reviews quarterly.

Data Protection: AES-256 encryption at rest, TLS 1.2+ in transit. UK GDPR compliant with documented data retention (user data: 90 days post-contract; business data: 7 years regulatory). Azure Key Vault for secrets management with quarterly rotation.

Vulnerability & Risk Management: Automated scanning via Trivy (CI/CD container scanning) and OWASP ZAP (weekly baseline, monthly full scans). Microsoft Defender suite deployed (Endpoint, Containers, Storage). Critical CVEs patched within 24 hours. High-severity alerts acknowledged within 1 business day.

Incident Response: Documented procedures with severity-based SLAs. Post-incident analysis mandatory for P1/P2 issues. Comprehensive audit logging retained 13 months.

Business Continuity: Daily automated backups, 30-day retention, zone-redundant storage. Point-in-time restore capability (RPO: 5 minutes; RTO: 4 hours).

Certifications: Cyber Essentials target Q3 2026, ISO 27001 alignment in progress.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
CONFIGURATION AND CHANGE MANAGEMENT:

All changes deployed via automated CI/CD pipelines with mandatory security gates. Trivy blocks CRITICAL vulnerabilities pre-deployment; OWASP ZAP validates runtime security (weekly baseline, monthly full scans).

Production changes require code review and approval. Infrastructure-as-Code manages all configurations with version control. Azure Policy Assignments enforce security baselines.

Patch Management: Critical CVEs within 24 hours. AKS auto-patched; application dependencies updated monthly minimum.

Audit Trail: All deployments logged (timestamp, author, changes). Configuration compliance reviewed quarterly. Security Policy v3.0 maintained with quarterly reviews.

Working towards formal certification alignment (CSA CCM/ISO 27001) by 2027.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Automated Scanning:
- Trivy container scanning in CI/CD blocks CRITICAL vulnerabilities pre-deployment
- OWASP ZAP scans: weekly baseline, monthly full active scans on all public endpoints
- Microsoft Defender suite (Endpoint, Containers, Storage) provides runtime monitoring

Remediation SLAs:
- CRITICAL vulnerabilities: 7 days maximum
- Base images refreshed monthly or upon critical CVE advisories
- Application dependencies updated monthly minimum

Monitoring & Response:
- P1 alerts acknowledged and triaged within 1 business day
- Security scan artifacts retained 13 months for audit trail
- Weekly review of Defender for Cloud recommendations
- Quarterly security reporting
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Real-Time Monitoring:
- Microsoft Defender for Cloud monitors all Azure resources with automated alerting
- Defender for Endpoint (EDR) on AKS nodes provides anti-malware and behavioral detection
- Sentry monitors application exceptions and security events
- Network monitoring via Azure Application Gateway and Firewall

Security Alerting:
- High-severity alerts notify Security Admins within 15 minutes
- P1 alerts acknowledged within 1 business day
- Weekly security recommendation reviews

Audit Logging:
- Comprehensive logging of authentication, access attempts, permission changes
- Activity logs retained 13 months (immutable, PII-excluded)
- Monthly reporting tracks alert volumes, vulnerability findings, SLA adherence
Incident management type
Supplier-defined controls
Incident management approach
JustFarm maintains documented incident procedures with severity-based classification (P1/P2/P3) and defined SLAs. P1 incidents receive acknowledgment within 1 business day with immediate containment. Pre-defined playbooks exist for security breaches, outages, and common events. Automated monitoring via Microsoft Defender and Sentry triggers incident workflows.

Incident reporting includes: initial notification within 15 minutes, hourly progress updates, immediate resolution communication, and root cause analysis within 48 hours for major incidents. All incidents tracked with mandatory post-mortems for P1/P2, ensuring continuous improvement.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Users can create their farm, upload their agreement documents and see their ELMs actions mapped over their farm. Users can then view advice on what they need to do to stay compliant.
Link to free trial
https://justfarm.app

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
20%
Between £250,000 and £500,000
20%
Between £500,001 and £1,000,000
20%
Between £1,000,001 and £2,500,000
25%
Between £2,500,001 and £5,000,000
25%
Over £5,000,001
30%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at contact@justfarm.app. Tell them what format you need. It will help if you say what assistive technology you use.