๐Ÿ” Legal

Security Policy

How we protect your data, what to do on your end, and how to report a vulnerability responsibly.

Last updated: July 17, 2026 ยท Version 1.0

This Security Policy describes the technical and organizational measures AYE Tech Hub takes to protect user data on the AYE Market app and website (the "Service"), what's expected of you as a user, and how to responsibly report a security vulnerability. It complements our Privacy Policy, which covers what data we collect and why.

Contents
  1. Our security measures
  2. Access control
  3. Your security responsibilities
  4. Reporting a vulnerability
  5. In the event of a breach
  6. Applicable law
  7. Changes
  8. Contact

1. Our security measures

2. Access control

Internal access to user data is limited to what a given team needs to do its job โ€” verification reviewers see submitted ID documents, payment reviewers see payment receipts, and moderators see reported content. This separation limits what any single compromised account or point of failure could expose.

3. Your security responsibilities

4. Reporting a vulnerability

If you discover a security vulnerability in the AYE Market app, website, or backend, we want to hear about it before anyone else does. Email ayetechub@gmail.com with:

Please report responsibly: don't access, modify, or delete data beyond what's necessary to demonstrate the issue, and don't publicly disclose a vulnerability until we've had a reasonable opportunity to investigate and fix it. We commit to acknowledging genuine reports and working in good faith with anyone who reports responsibly.

5. In the event of a breach

If a security incident is confirmed to have exposed user data, we will investigate, take steps to contain and remediate it, and notify affected users and any relevant authority as required by applicable law, consistent with the data protection commitments in our Privacy Policy.

6. Applicable law

This policy is governed by the laws of the Federal Democratic Republic of Ethiopia, including applicable data protection requirements.

7. Changes to this policy

We may update this policy as our security practices evolve. Material changes are reflected by updating the "Last updated" date above.

8. Contact

Security questions or vulnerability reports: ayetechub@gmail.com.