This Security Policy describes the technical and organizational measures AYE Tech Hub takes to protect user data on the AYE Market app and website (the "Service"), what's expected of you as a user, and how to responsibly report a security vulnerability. It complements our Privacy Policy, which covers what data we collect and why.
1. Our security measures
- Encryption in transit โ all communication between the app and our backend is encrypted using HTTPS/TLS.
- Encryption at rest โ data stored in Firebase (Cloud Firestore and Firebase Storage) is encrypted at rest, as provided by Google's Firebase platform.
- Firestore security rules โ server-side rules enforce per-user data access on a least-privilege basis: you can read and write your own data, and only the specific data others have made public (listings, public profile fields) is visible to them.
- Restricted access to sensitive documents โ ID verification documents (Fayda ID, Kebele Residence ID, Driver's License, Business License, Passport) and payment receipts are restricted to our verification and payment review teams only; they are never visible to other users, including the seller's own buyers.
- Server-side enforcement of sensitive actions โ approving a verification or payment request, or deleting an account, is performed exclusively through server-side Cloud Functions after an administrator's explicit action, never trusted from the client app alone.
- Logged admin actions โ moderation and administrative actions taken on accounts and content are logged for accountability.
2. Access control
Internal access to user data is limited to what a given team needs to do its job โ verification reviewers see submitted ID documents, payment reviewers see payment receipts, and moderators see reported content. This separation limits what any single compromised account or point of failure could expose.
3. Your security responsibilities
- Use a strong, unique password for your AYE Market account โ not one reused from another service.
- Never share an OTP code with anyone. Neither AYE Market staff nor a legitimate buyer or seller will ever legitimately ask you for one โ a request for your OTP is always a red flag. See our Fraud Prevention Policy.
- Recognize phishing attempts โ be suspicious of links sent in chat asking you to log in or enter payment details; AYE Market never requests this through in-app chat.
- Keep the app updated to the latest version, so you have current security fixes.
- Sign in with Google or Facebook where convenient โ these benefit from that provider's own account security, in addition to email/password and phone sign-in options.
- Report a compromised account to us immediately if you notice activity you didn't perform.
4. Reporting a vulnerability
If you discover a security vulnerability in the AYE Market app, website, or backend, we want to hear about it before anyone else does. Email ayetechub@gmail.com with:
- A clear description of the vulnerability and its potential impact.
- Steps to reproduce it, if possible.
- Any relevant screenshots, logs, or proof-of-concept detail.
Please report responsibly: don't access, modify, or delete data beyond what's necessary to demonstrate the issue, and don't publicly disclose a vulnerability until we've had a reasonable opportunity to investigate and fix it. We commit to acknowledging genuine reports and working in good faith with anyone who reports responsibly.
5. In the event of a breach
If a security incident is confirmed to have exposed user data, we will investigate, take steps to contain and remediate it, and notify affected users and any relevant authority as required by applicable law, consistent with the data protection commitments in our Privacy Policy.
6. Applicable law
This policy is governed by the laws of the Federal Democratic Republic of Ethiopia, including applicable data protection requirements.
7. Changes to this policy
We may update this policy as our security practices evolve. Material changes are reflected by updating the "Last updated" date above.
8. Contact
Security questions or vulnerability reports: ayetechub@gmail.com.