Security & Vulnerability Disclosure

Last updated: September 2026

1. Our security posture

Changes made in the partner portal, and changes our operations team makes to a salon’s account, write a hash-chained audit row; a few write paths do not yet, and we are closing them before launch. Production secrets live in our hosting provider’s environment settings, never in our source code. Refunds and payout changes require a fresh step-up check.

We’re not certified ourselves. We plan a SOC 2 Type II audit after launch; until an auditor has reported, the statements below describe what we run today, not what an auditor has checked.

2. Infrastructure

  • Built on SOC 2 Type II + ISO 27001 certified infrastructure: Supabase for the database, Vercel for hosting and Cloudflare R2 for file storage. HIPAA Business Associate Agreements with these vendors are pending.
  • Payments in Ghana are processed by Paystack, PCI-DSS Level 1 certified. Card details are entered in Paystack’s own payment form, so Slotlyy never stores or transmits raw card data.
  • Data is encrypted at rest by our infrastructure providers (AES-256) and in transit with TLS. Field-level encryption of personal data in audit records, with a separate key for each salon, is in development.
  • Hash-chained audit logs: each entry carries a hash of the one before it, so an altered entry can be detected when the chain is checked. The daily chain check and archival to write-once storage are planned and not yet running.
  • HIPAA-aligned posture: a Business Associate Agreement will be offered to covered entities (medical-adjacent spa, massage and wellness salons) once Slotlyy’s company registration and our vendors’ agreements are complete. We do not offer one today.
  • A documented mapping of our security controls to the NIST Cybersecurity Framework is planned. We will publish it before describing our controls as aligned with the framework.

3. Compliance & data protection

Slotlyy operates in Ghana today. Our data-protection programme is designed to meet the requirements of the Ghana Data Protection Act 2012 (Act 843), and our registration with the Data Protection Commission is in progress. We will add each country’s data-protection law to this page when we launch there.

We are not in scope for EU GDPR. Our Privacy Policy and Data Processing Addendum (DPA, available on request) are drafts awaiting counsel review, and are scoped to African frameworks.

4. Vulnerability disclosure

We welcome reports from security researchers. Please email [email protected] before disclosing publicly, with steps to reproduce.

Our RFC 9116 contact record: /.well-known/security.txt.

In-scope:

  • Authentication bypass or session-handling weaknesses
  • Authorization flaws (IDOR, privilege escalation, cross-tenant access)
  • Injection vulnerabilities (SQL, XSS, SSRF, command injection)
  • Cryptographic weaknesses (weak random, key handling, signature bypass)
  • Sensitive data exposure or PII / PHI leakage
  • Webhook signature bypass or replay attacks
  • Rate-limit bypass on financial or authentication surfaces

Out-of-scope:

  • Denial of Service (volumetric or application-layer) — please do not test against production
  • Social engineering of our staff or customers
  • Physical attacks against infrastructure
  • Vulnerabilities in third-party services (Paystack, Vercel, Supabase, Cloudflare) — report directly to the vendor
  • Self-XSS in unauthenticated contexts
  • Missing best-practice security headers without demonstrated impact

5. Bug bounty programme

We do not run a paid bug bounty programme yet. Until we do, we acknowledge researchers who report valid vulnerabilities on this page, with their permission.

6. Acknowledgments

We’re grateful to the security community for keeping our customers safe. Researchers who report valid vulnerabilities and consent to attribution are listed here:

No acknowledgments yet — be the first.

7. Out-of-band contact

For sensitive reports (active exploitation, large-scale data exposure, or vulnerabilities affecting multiple salons at once), please use the same email [email protected] and mark the subject line with [URGENT]. We plan to publish a PGP key alongside a formal bug bounty programme.