Vulnerability Disclosure
How to report a security issue to AfriScore — scope, safe harbor, and process.
AfriScore welcomes reports of security vulnerabilities in our systems. If you are a security researcher, an engineer, or a user who has identified a potential issue, this page explains how to report it, what is in scope, and what you can expect in return.
How to report
Send your report to:
Please include as much of the following as possible:
- A clear description of the vulnerability
- The system, endpoint, or component affected
- Steps to reproduce the issue
- The potential impact, in your assessment
- Any proof-of-concept code or screenshots
- Your preferred contact method and, if you wish, your name for credit
Encrypt sensitive reports if you prefer. Our PGP public key is available on request to security@afriscore.africa.
Response timeline
AfriScore commits to the following response times for vulnerability reports:
- Acknowledgement of report: Within 72 hours
- Initial assessment (severity and scope): Within 7 days
- Fix or mitigation plan communicated: Within 30 days for high-severity issues
- Public disclosure coordination: By mutual agreement, after a fix is deployed
You will receive a human response. Reports are not triaged by an automated system.
Scope
The following systems are in scope for vulnerability disclosure:
- afriscore.africa — Marketing site and public application forms
- trust.afriscore.africa — Trust center (this site)
- developer.afriscore.africa — Developer documentation
- api.afriscore.africa — Production API (once live)
- charlesmfouapon.com — Founder's personal site
Out of scope
The following are not eligible for disclosure credit or investigation:
- Third-party services used by AfriScore (report those directly to the vendor)
- Social engineering attacks against AfriScore personnel
- Denial-of-service attacks
- Physical security of AfriScore offices or personnel
- Issues requiring physical access to a user's device
- Vulnerabilities in outdated browsers or unsupported platforms
- Self-XSS and clickjacking on pages with no sensitive actions
Safe harbor
AfriScore will not pursue legal action against researchers who report vulnerabilities in good faith.
Specifically, AfriScore commits to:
- Not initiating legal action related to your research, provided you comply with this policy
- Not reporting your activity to law enforcement
- Working with you to understand and resolve the issue quickly
- Recognizing your contribution publicly, if you wish, once a fix is deployed
To qualify for safe harbor, you must:
- Make a good-faith effort to avoid privacy violations, data destruction, and service interruption
- Only interact with accounts you own or have explicit permission to access
- Not exploit a vulnerability beyond what is necessary to demonstrate it
- Not disclose the vulnerability publicly before a fix is deployed, without mutual agreement
What we ask of you
- Give us reasonable time to respond and remediate before public disclosure
- Do not access, modify, or delete data belonging to others
- Do not use the vulnerability to pivot to other systems
- Do not run automated scanners against production systems at high volume
Recognition
AfriScore does not currently operate a paid bug bounty program. We do provide:
- Public credit on this page (with your permission) once a fix is deployed
- A direct reference for future employment or contracting discussions, if you are interested
- A letter of acknowledgement for your portfolio
A formal bug bounty program is on the roadmap and will be launched alongside the first enterprise-grade contract. Until then, disclosure is voluntary and unpaid.
What we commit to
- Every report receives a human response within 72 hours
- We will not close a report without explanation
- If we determine that a reported issue is out of scope, we will say why
- If a fix is delayed, we will explain the delay
- If your report leads to a fix, we will credit you publicly, unless you prefer to remain anonymous
Contact
For all vulnerability disclosures:
For general security questions: