# Slotlyy — Vulnerability Disclosure Policy (RFC 9116 security.txt) # # We welcome reports from security researchers. Please contact us at the # address below before disclosing publicly, with steps to reproduce. # # Out-of-scope: # - Denial of Service (volumetric or application-layer) — please do not # test against our production infrastructure. # - Social engineering of our staff or customers. # - Physical attacks against our infrastructure. # - Vulnerabilities in third-party services (Paystack, Vercel, Supabase, # Cloudflare R2, etc.) — please report those directly to the relevant # vendor. # # In-scope: any technical vulnerability in our codebase or infrastructure # that affects the confidentiality, integrity, or availability of customer # data — including but not limited to: authentication bypass, IDOR, # injection, SSRF, XSS, CSRF, sensitive data exposure, broken access # control, and any cryptographic weakness. # # We do not run a paid bug bounty programme yet. Until we do, we # acknowledge researchers who report valid vulnerabilities on our # /security page, with their permission. # # Slotlyy operates in Ghana today. We are not in scope for EU GDPR; the # Ghana Data Protection Act 2012 (Act 843) is the applicable # data-protection framework. Contact: mailto:sec@slotlyy.com Expires: 2026-12-31T23:59:59Z Preferred-Languages: en Canonical: https://slotlyy.com/.well-known/security.txt Policy: https://slotlyy.com/security Acknowledgments: https://slotlyy.com/security#acknowledgments