Legal

Security

How we protect systems and data, and how to report a vulnerability responsibly.

Last updated: 9 August 2026

1. Our approach

Devslab Ltd builds and operates software for businesses, public institutions, and our own products. Security is part of how we design, deliver, and support systems — not an afterthought.

This page summarizes our practices for visitors, clients, and researchers. Detailed controls for a specific engagement are defined in the relevant contract, architecture, or product documentation.

2. How we protect systems

Depending on the project or product, we typically apply:

  • Secure development practices: least privilege, input validation, dependency hygiene, and code review.
  • Encrypted transport (HTTPS/TLS) for public sites and APIs we operate.
  • Access control for admin tools, environments, and customer data, with authentication appropriate to the risk.
  • Hosting and infrastructure choices that support backups, monitoring, and isolation where needed.
  • Vendor diligence for email, databases, and other processors that handle personal or client data.

3. Client and product engagements

For custom software and managed products (including platforms such as SitBites, Gemura, and Orora), security requirements, hosting regions, and audit expectations are agreed per engagement. We align delivery with those requirements and communicate material risks we identify during the work.

4. Personal data

How we collect and use personal information on our website and talent network is described in our Privacy Policy. We limit access to personal data to people and systems that need it for a legitimate purpose.

5. Responsible disclosure

If you believe you have found a security vulnerability in a Devslab-operated website, API, or product, please tell us privately so we can investigate and fix it.

  • Email security reports to hello@devslab.io with the subject line “Security disclosure”.
  • Include steps to reproduce, affected URLs or endpoints, and potential impact if known.
  • Give us a reasonable time to respond before public disclosure.
  • Do not access or modify data that is not yours, disrupt services, or use social engineering against our staff or clients.

6. What we ask researchers to avoid

Do not run denial-of-service tests, spam users, phishing campaigns, or physical attacks. Do not attempt to exploit a finding beyond what is needed to demonstrate it. Out-of-scope items include third-party services we do not control and non-security issues such as spelling errors.

7. Contact

Security reports: hello@devslab.io (subject: Security disclosure)

Privacy & data requests: privacy@devslab.io

Devslab Ltd · Kigali, Rwanda (HQ) · https://www.devslab.io

Questions about this policy? hello@devslab.io

Privacy Policy