AfriScore Trust

Vulnerability Disclosure

How to report a security issue to AfriScore — scope, safe harbor, and process.

AfriScore welcomes reports of security vulnerabilities in our systems. If you are a security researcher, an engineer, or a user who has identified a potential issue, this page explains how to report it, what is in scope, and what you can expect in return.

How to report

Send your report to:

security@afriscore.africa

Please include as much of the following as possible:

  • A clear description of the vulnerability
  • The system, endpoint, or component affected
  • Steps to reproduce the issue
  • The potential impact, in your assessment
  • Any proof-of-concept code or screenshots
  • Your preferred contact method and, if you wish, your name for credit

Encrypt sensitive reports if you prefer. Our PGP public key is available on request to security@afriscore.africa.

Response timeline

AfriScore commits to the following response times for vulnerability reports:

  • Acknowledgement of report: Within 72 hours
  • Initial assessment (severity and scope): Within 7 days
  • Fix or mitigation plan communicated: Within 30 days for high-severity issues
  • Public disclosure coordination: By mutual agreement, after a fix is deployed

You will receive a human response. Reports are not triaged by an automated system.

Scope

The following systems are in scope for vulnerability disclosure:

  • afriscore.africa — Marketing site and public application forms
  • trust.afriscore.africa — Trust center (this site)
  • developer.afriscore.africa — Developer documentation
  • api.afriscore.africa — Production API (once live)
  • charlesmfouapon.com — Founder's personal site

Out of scope

The following are not eligible for disclosure credit or investigation:

  • Third-party services used by AfriScore (report those directly to the vendor)
  • Social engineering attacks against AfriScore personnel
  • Denial-of-service attacks
  • Physical security of AfriScore offices or personnel
  • Issues requiring physical access to a user's device
  • Vulnerabilities in outdated browsers or unsupported platforms
  • Self-XSS and clickjacking on pages with no sensitive actions

Safe harbor

AfriScore will not pursue legal action against researchers who report vulnerabilities in good faith.

Specifically, AfriScore commits to:

  • Not initiating legal action related to your research, provided you comply with this policy
  • Not reporting your activity to law enforcement
  • Working with you to understand and resolve the issue quickly
  • Recognizing your contribution publicly, if you wish, once a fix is deployed

To qualify for safe harbor, you must:

  • Make a good-faith effort to avoid privacy violations, data destruction, and service interruption
  • Only interact with accounts you own or have explicit permission to access
  • Not exploit a vulnerability beyond what is necessary to demonstrate it
  • Not disclose the vulnerability publicly before a fix is deployed, without mutual agreement

What we ask of you

  • Give us reasonable time to respond and remediate before public disclosure
  • Do not access, modify, or delete data belonging to others
  • Do not use the vulnerability to pivot to other systems
  • Do not run automated scanners against production systems at high volume

Recognition

AfriScore does not currently operate a paid bug bounty program. We do provide:

  • Public credit on this page (with your permission) once a fix is deployed
  • A direct reference for future employment or contracting discussions, if you are interested
  • A letter of acknowledgement for your portfolio

A formal bug bounty program is on the roadmap and will be launched alongside the first enterprise-grade contract. Until then, disclosure is voluntary and unpaid.

What we commit to

  • Every report receives a human response within 72 hours
  • We will not close a report without explanation
  • If we determine that a reported issue is out of scope, we will say why
  • If a fix is delayed, we will explain the delay
  • If your report leads to a fix, we will credit you publicly, unless you prefer to remain anonymous

Contact

For all vulnerability disclosures:

security@afriscore.africa

For general security questions:

security@afriscore.africa