ZamaniFlow Legal

Security Policy

Our public security commitments, and how to report a security issue responsibly.

Policy version v1.0·Effective September 2026

ZamaniFlow is developed and operated by ZAMANI DYNAMICS, a registered business in Dakar, Senegal. Business information

01.Security Principles

  • Least privilege and role-based access.
  • Encryption in transit for supported web, app, API, and administrative traffic.
  • Secure secret and API-key management; no secrets committed to public source code.
  • Strong password hashing and secure authentication controls.
  • Environment separation and restricted production access.
  • Logging and monitoring of security-relevant events.
  • Backups, recovery procedures, patching, dependency monitoring, and vulnerability management.
  • Data minimization and controlled retention.

02.Payment and API Security

Payment integrations should use provider-issued credentials stored in a secure secret-management mechanism. Webhooks should be authenticated or cryptographically verified where supported. Production keys should be separate from development/test keys. ZamaniFlow should minimize storage of sensitive payment credentials and rely on authorized payment providers for regulated payment processing.

03.Secure Development

Production changes should follow controlled development, review, testing, and deployment procedures. Security-sensitive changes require appropriate review. Dependencies should be monitored for known vulnerabilities and updated according to risk.

04.Incident Response

Suspected incidents should be triaged, contained, investigated, remediated, documented, and escalated. ZamaniFlow should preserve relevant evidence and make regulatory, contractual, merchant, or user notifications when required.

05.Merchant Responsibilities

  • Protect administrator credentials and devices.
  • Remove access promptly when staff leave or change roles.
  • Use individual accounts rather than shared credentials where possible.
  • Notify ZamaniFlow promptly of suspected unauthorized access.

06.Responsible Reporting

Security issues should be reported privately to admin@zamaniflow.com. Researchers and users must not exploit vulnerabilities, access others’ data, disrupt service, or publicly disclose unresolved issues in a way that creates unnecessary risk.