Legal Center

Dafluma legal

Controlled draft

Security Policy

User security responsibilities and responsible vulnerability reporting.

Version
1.0
Effective
2026-08-06
Applies to
Users and security researchers

Controlled draft

This document is versioned but is not a current published policy. Refer to its publication status in the Legal Center.

Protecting your account

  • Use a unique password and the strongest available multi-factor authentication.
  • Never share OTPs, recovery codes, session cookies, or payment PINs.
  • Verify the domain and payment prompt before approving a request.
  • Sign out of shared devices and report suspicious activity promptly.

Responsible disclosure

Report a suspected vulnerability privately to security@dafluma.com. Include reproducible detail without accessing more data than necessary. Do not disrupt services, perform social engineering, demand payment, publish secrets, or exploit a vulnerability after confirming it.

What to expect

We aim to acknowledge reports, assess severity, preserve evidence, remediate proportionately, and communicate status where appropriate. This policy is not a bug-bounty promise and does not authorize unlawful testing.

Operator: IWEBZ KENYA LTD

Platform: Dafluma

Contact: legal@dafluma.com

Address: Westlands, Nairobi, Kenya