Responsible Disclosure Policy

Last updated: 2026-07-17

DRAFT (revamp 2026-07) — for SA attorney review only. Not legal advice. Not for publication.
All statutory references in this draft are indicative and must be verified by counsel against the current text of each Act before any reliance or publication.
Placeholders marked [TBD: …] require factual confirmation. Items marked [ATTORNEY-REQUIRED: …] require legal advice before this document may be finalised or published.

eRunna takes the security of our platform, systems, and the personal information we process seriously. We welcome good-faith reports from security researchers, customers, runners, merchants, and members of the public about potential vulnerabilities in our Services. This Responsible Disclosure Policy explains how to report a vulnerability, what you can expect from us, and how we will handle your report.

This policy is intended to be read together with our Security Incident Response Plan and our Privacy Policy. It applies to all digital surfaces operated by eRunna, including the eRunna mobile applications (iOS and Android), the eRunna web platform, the merchant portal, and associated back-end systems and APIs.

1. How to report a vulnerability

If you discover a security vulnerability or suspected vulnerability in any eRunna system, please report it to us before disclosing it publicly. To report a vulnerability:

2. What to expect from us

We commit to the following response timelines for good-faith reports received at the designated security address:

We ask for your patience during the assessment and remediation process. We request that you do not publicly disclose details of the vulnerability until we have had a reasonable opportunity to investigate and remediate it. We aim to agree a public-disclosure timeline with you where relevant.

3. Scope

In scope — we welcome reports relating to:

Out of scope — please do not test for or report the following:

4. Good-faith requirements

This policy is extended to security researchers who act in good faith. Good-faith conduct means:

5. Safe harbour

Where a security researcher reports a vulnerability to us in good faith and in compliance with this policy, eRunna will:

[ATTORNEY-REQUIRED: Safe-harbour assurances in a voluntary disclosure policy have no binding legal force unless they are appropriately drafted as a contractual commitment or covenant not to sue. Counsel must advise: (a) whether this safe-harbour paragraph creates any enforceable commitment under South African law; (b) how to draft a safe-harbour provision that is both meaningful and does not inadvertently waive eRunna's rights against bad-faith actors; (c) whether specific language under the Cybercrimes Act [ATTORNEY-REQUIRED: confirm citation — Act number and year] or ECTA is required or beneficial; and (d) what limitations should be expressly stated (e.g. the safe harbour does not apply where the researcher exceeded the scope of this policy, caused harm, or acted in bad faith). This paragraph must be reviewed and approved by counsel before publication.]

This policy does not authorise any testing, access, or conduct that would constitute an offence under the Cybercrimes Act [ATTORNEY-REQUIRED: confirm citation — Act number and year], the ECTA, or any other applicable South African or international law. Researchers who act outside the scope of this policy or in bad faith are not covered by any assurance in this section.

6. Personal information in security reports

Security research may sometimes surface personal information belonging to real users. If you encounter personal information in the course of your research:

eRunna will handle your report and any personal information you share with us in accordance with our Privacy Policy and the Protection of Personal Information Act [ATTORNEY-REQUIRED: confirm citation — Act number and year] ("POPIA").

POPIA — security compromise notification [ATTORNEY-REQUIRED: confirm citation — section number, trigger, and notification timing]: Where a security vulnerability or incident involves or may involve a compromise of personal information of eRunna's data subjects, eRunna may be required under POPIA to notify the Information Regulator and affected data subjects following discovery of the compromise. [ATTORNEY-REQUIRED: confirm the governing section of POPIA (the drafter's belief is section 22), the precise conditions that trigger the notification duty, and the required timing (e.g. "as soon as reasonably possible after discovery"), each verified against the current text of the Act.] Your prompt report to us supports our ability to meet these obligations.

7. Recognition

We appreciate the contribution of security researchers who help us keep the platform safe. With your permission, we may acknowledge your contribution publicly (for example, in a Hall of Thanks or in our release notes). We will always ask for your permission before naming you publicly.

[TBD: confirm whether a formal bug-bounty programme with monetary rewards is available or planned. If so, include eligibility criteria, reward ranges, and the platform or process for claim submission here. If not, remove the monetary-reward reference and retain acknowledgement only.]

8. Contact

Related policies