DRAFT (revamp 2026-07) — for SA attorney review only. Not legal advice. Not for publication.
All statutory references in this draft are indicative and must be verified by counsel against the current text of each Act before any reliance or publication.
Placeholders marked [TBD: …] require factual confirmation. Items marked [ATTORNEY-REQUIRED: …] require legal advice before this document may be finalised or published.
eRunna takes the security of our platform, systems, and the personal information we process seriously. We welcome good-faith reports from security researchers, customers, runners, merchants, and members of the public about potential vulnerabilities in our Services. This Responsible Disclosure Policy explains how to report a vulnerability, what you can expect from us, and how we will handle your report.
This policy is intended to be read together with our Security Incident Response Plan and our Privacy Policy. It applies to all digital surfaces operated by eRunna, including the eRunna mobile applications (iOS and Android), the eRunna web platform, the merchant portal, and associated back-end systems and APIs.
1. How to report a vulnerability
If you discover a security vulnerability or suspected vulnerability in any eRunna system, please report it to us before disclosing it publicly. To report a vulnerability:
- Email: Send a detailed report to security@erunna.app [TBD: confirm whether this dedicated security address is active; if not, fall back to info@erunna.app with subject line "SECURITY — Responsible Disclosure"]. Mark the subject line:
SECURITY — Responsible Disclosure. - Encryption: [TBD: if a PGP public key is available for encrypted submission, publish the key or a link here. If not yet available, remove this bullet before publication.]
- What to include in your report:
- A clear description of the vulnerability and the potential impact.
- The affected system, URL, endpoint, or component (as specific as possible).
- Step-by-step instructions to reproduce the vulnerability.
- Proof-of-concept code, screenshots, screen recordings, or HTTP request/response samples where relevant.
- Your name and contact details (optional, but required if you wish to be acknowledged or notified of resolution).
2. What to expect from us
We commit to the following response timelines for good-faith reports received at the designated security address:
- Acknowledgement: We aim to acknowledge receipt of your report within three (3) business days.
- Initial assessment: We aim to provide an initial assessment of severity and validity within ten (10) business days of acknowledgement.
- Remediation updates: We will keep you reasonably informed of our progress. Resolution timelines depend on complexity and severity; critical vulnerabilities are prioritised. We will notify you when the issue has been remediated or when we have determined that no action is required.
- Closure notification: We will notify you when the reported issue has been closed.
We ask for your patience during the assessment and remediation process. We request that you do not publicly disclose details of the vulnerability until we have had a reasonable opportunity to investigate and remediate it. We aim to agree a public-disclosure timeline with you where relevant.
3. Scope
In scope — we welcome reports relating to:
- Authentication and authorisation vulnerabilities (including broken access control, privilege escalation, and session management).
- Injection vulnerabilities (SQL injection, NoSQL injection, command injection).
- Exposure of personal information or sensitive financial data (including POPIA-notifiable data leaks).
- Cross-site scripting (XSS), cross-site request forgery (CSRF), and server-side request forgery (SSRF).
- Insecure direct object references (IDOR / BOLA) and broken object-level authorisation.
- Payment processing vulnerabilities or unauthorised access to transaction data.
- Vulnerabilities in the eRunna mobile applications (iOS and Android).
- Vulnerabilities in back-end APIs, the merchant portal, or the eRunna web platform.
- Security misconfigurations in our cloud infrastructure that expose data or functionality.
Out of scope — please do not test for or report the following:
- Vulnerabilities in third-party services, applications, or platforms that we do not control (including but not limited to Paystack, Firebase, Google Cloud Platform services, and app-store infrastructure). Please report those directly to the relevant third party.
- Physical security testing, social engineering, phishing, or attacks targeting eRunna employees, customers, runners, or merchants.
- Denial-of-service (DoS/DDoS) attacks or volume-based testing against production systems.
- Automated scanning without prior written permission — automated scans against production systems cause real harm and are not permitted under this policy.
- Theoretical vulnerabilities without a working proof of concept demonstrating real-world impact.
- Issues affecting only outdated or unsupported browser or OS versions.
- Missing security headers that have no demonstrated exploitability on our specific deployment.
- Self-XSS or vulnerabilities that require unlikely or contrived user interaction that would not occur in practice.
- Rate-limiting issues that do not expose sensitive data or functionality.
4. Good-faith requirements
This policy is extended to security researchers who act in good faith. Good-faith conduct means:
- Only testing against systems and accounts you own or that you have explicit permission to test. Do not access, modify, or exfiltrate data belonging to real customers, runners, merchants, or partners.
- Not disrupting the availability of the Services or degrading the experience of other users.
- Not accessing more data than is strictly necessary to demonstrate the vulnerability.
- Reporting the issue to us promptly and privately before any public disclosure.
- Not using the vulnerability for personal gain, and not sharing it with third parties without our written consent.
- Acting within the boundaries of applicable South African law, including the Cybercrimes Act [ATTORNEY-REQUIRED: confirm citation — Act number and year] and the Electronic Communications and Transactions Act [ATTORNEY-REQUIRED: confirm citation — Act number and year] ("ECTA").
5. Safe harbour
Where a security researcher reports a vulnerability to us in good faith and in compliance with this policy, eRunna will:
- Work with the researcher in good faith to understand and resolve the issue.
- Not pursue civil or criminal legal action against the researcher solely for the act of discovering and responsibly disclosing a vulnerability in accordance with this policy.
[ATTORNEY-REQUIRED: Safe-harbour assurances in a voluntary disclosure policy have no binding legal force unless they are appropriately drafted as a contractual commitment or covenant not to sue. Counsel must advise: (a) whether this safe-harbour paragraph creates any enforceable commitment under South African law; (b) how to draft a safe-harbour provision that is both meaningful and does not inadvertently waive eRunna's rights against bad-faith actors; (c) whether specific language under the Cybercrimes Act [ATTORNEY-REQUIRED: confirm citation — Act number and year] or ECTA is required or beneficial; and (d) what limitations should be expressly stated (e.g. the safe harbour does not apply where the researcher exceeded the scope of this policy, caused harm, or acted in bad faith). This paragraph must be reviewed and approved by counsel before publication.]
This policy does not authorise any testing, access, or conduct that would constitute an offence under the Cybercrimes Act [ATTORNEY-REQUIRED: confirm citation — Act number and year], the ECTA, or any other applicable South African or international law. Researchers who act outside the scope of this policy or in bad faith are not covered by any assurance in this section.
6. Personal information in security reports
Security research may sometimes surface personal information belonging to real users. If you encounter personal information in the course of your research:
- Do not access, copy, store, transmit, or use personal information beyond the minimum necessary to demonstrate the vulnerability.
- Notify us immediately that personal information was encountered.
- Delete or destroy any personal information you have accessed as soon as you have provided sufficient evidence to us.
eRunna will handle your report and any personal information you share with us in accordance with our Privacy Policy and the Protection of Personal Information Act [ATTORNEY-REQUIRED: confirm citation — Act number and year] ("POPIA").
POPIA — security compromise notification [ATTORNEY-REQUIRED: confirm citation — section number, trigger, and notification timing]: Where a security vulnerability or incident involves or may involve a compromise of personal information of eRunna's data subjects, eRunna may be required under POPIA to notify the Information Regulator and affected data subjects following discovery of the compromise. [ATTORNEY-REQUIRED: confirm the governing section of POPIA (the drafter's belief is section 22), the precise conditions that trigger the notification duty, and the required timing (e.g. "as soon as reasonably possible after discovery"), each verified against the current text of the Act.] Your prompt report to us supports our ability to meet these obligations.
7. Recognition
We appreciate the contribution of security researchers who help us keep the platform safe. With your permission, we may acknowledge your contribution publicly (for example, in a Hall of Thanks or in our release notes). We will always ask for your permission before naming you publicly.
[TBD: confirm whether a formal bug-bounty programme with monetary rewards is available or planned. If so, include eligibility criteria, reward ranges, and the platform or process for claim submission here. If not, remove the monetary-reward reference and retain acknowledgement only.]
8. Contact
- Security disclosures: security@erunna.app [TBD: confirm active status] — subject line:
SECURITY — Responsible Disclosure - General enquiries: info@erunna.app | 010 140 6554
- POPIA Information Officer (data-subject rights and breaches): [TBD: name and direct contact of the designated Information Officer registered with the Information Regulator]
- Information Regulator (South Africa): www.inforegulator.org.za
Related policies
- Security Incident Response Plan — how eRunna detects, contains, and responds to security incidents
- Privacy Policy — how we collect, use, and protect your personal information (POPIA)
- Terms of Service — general platform terms including acceptable use
- Data Retention Policy — how long we keep data and why