Légal

Vulnerability disclosure policy

Dernière mise à jour : 11 September 2026 · [email protected] · +221 78 110 54 54

Contents

How to report a vulnerability

Email [email protected]. It is the only dedicated address, and it is also published in machine-readable form in our security.txt file.

Please do not use sales support, the contact form or social media for a security issue: those channels are read by people who cannot act on it, and a report waits there far longer than it should.

Scope

In scope:

Out of scope, and not processed:

What we commit to

What we ask of you

Rewards

To be plain about where we stand: we do not run a bug bounty yet. Today, no report, whatever its severity, results in a payment, a voucher or any commercial consideration — and we would rather write that down than let anyone hope for one only to turn them down later.

This is not a matter of principle, it is a matter of cash. We are a young company, and a bounty programme opened without the means to honour it does more damage than no programme at all.

Our commitment: we will open a reward programme — material or financial — once we reach profitability or close a funding round. When that day comes, researchers who reported to us before the programme opened will not be forgotten: we keep the list, and that is exactly what it is for.

Until then, what we do offer is smaller and we stand by it: a fast reply written by someone who understands the subject, a fix, and your name in our hall of fame if you want it.

What makes a report useful

A good report saves us days. Tell us, even briefly:

A screenshot or a short video is often worth more than a long paragraph — but never of real data. Create a test company, or blur before sending. If the demonstration requires opening a real customer record, describe the path rather than its contents: we will reproduce it on our side.

This is not a formality. A report containing one of our merchants' data becomes a breach of its own, and we have no legitimate reason to hold it in a mailbox. Stopping at the proof protects us both.

French and English suit us equally well.