1. How to report
Send vulnerability reports to security@verify.ug. Please include a clear description, reproduction steps, affected endpoints and any proof-of-concept material. Encrypt sensitive details with our PGP key on request.
2. Scope
- The Verify.ug web application and its public marketing site.
- Public REST APIs under the
/apinamespace. - Verification portal and citizen wallet flows.
3. Expected response timelines
- Acknowledgement: within 3 business days.
- Initial triage and severity assessment: within 7 business days.
- Progress updates: on a reasonable cadence until resolution.
4. Safe testing guidelines
- Do not access, modify or exfiltrate data that does not belong to you.
- Do not run automated scanners that generate excessive load.
- Use test accounts you create; do not target real institutions or citizens.
- Stop testing and report if you encounter personal data.
5. Coordinated disclosure
We aim to remediate before public disclosure. We will coordinate a timeline with you and credit researchers who wish to be named.
6. Out of scope
- Denial-of-service testing or resource exhaustion.
- Social engineering of employees, customers or citizens.
- Physical attacks on offices or infrastructure.
- Reports based solely on missing best-practice headers without demonstrable impact.
- Third-party services we do not operate.
7. Safe harbour
If you make a good-faith effort to comply with this policy, we will not pursue or support legal action against your research and will work with you to resolve issues quickly.
8. Contact
Security team: security@verify.ug. A PGP key placeholder is available on request.