Afer / Company / Security

Security

Version 1.0 (draft) Last updated: not yet published Applies to: all countries where Afër operates

How we protect accounts and payments, and how to report a vulnerability to us.

Draft placeholder. The structure below is ready for your legal text; nothing here is in force yet.
Section 01

Reporting a vulnerability

Where to send it, what to include, and our commitment not to pursue good-faith research.

Section 02

Scope

Which apps, domains and APIs are in scope, and what is out of scope.

Section 03

Response times

Acknowledgement, triage and fix targets.

Section 04

Account security

Phone verification, session handling, and what we will never ask you for.

Section 05

Payment security

How wallet balances and card top-ups are handled, and the single-use QR design.

Section 06

Data protection

Encryption in transit and at rest, access control and audit logging.

Section 07

Hall of thanks

Researchers who have reported responsibly.