Report a vulnerability
Buntu welcomes reports from security researchers and members of the public who identify potential vulnerabilities in our services.
Who we are
Buntu is responsible for the security of the Buntu shop, app and related systems, and for protecting the data of our customers, partners and employees.
How to report
Please send your report to security@buntu.rw, including a description of the issue, the affected address or feature, and the steps needed to reproduce it. Screenshots or recordings are helpful. If your report contains sensitive information, please indicate this in the first line of your message.
What to expect
We will acknowledge your report within three working days and keep you informed as we investigate. Where a vulnerability is confirmed, we will work to resolve it and let you know once it has been addressed.
Guidelines
Please do not carry out testing that could disrupt our services, and do not access, modify or delete data that does not belong to you. We ask that you allow us reasonable time to address an issue before disclosing it publicly. We will not take action against anyone who reports a vulnerability in good faith and in line with these guidelines.
- Contact
- security@buntu.rw
- First response
- Within three working days
- Bug bounty
- Not currently offered
Please note
This page is intended solely for reporting security vulnerabilities. Enquiries about orders, accounts or other matters sent to security@buntu.rw cannot be processed. Please contact support@buntu.rw instead.